Does application Spring4Shell- CVE-2022-22965 vulnerable if using spring-plugin-core : 1.2.0?

Viewed 630

Is the system affected by CVE-2022-22965 if it only uses spring-plugin-core from the mentioned impacted list?

Configuration

  • java 8
  • Spring boot : 2.2.6.RELEASE
  • Packaged as executable JAR
  • spring-plugin-core : 1.2.0.RELEASE
1 Answers
Related