Spring4Shell Vulnerability - CVE-2022-22965 #5123
-
Recently noticed a software vulnerability that affects JAVA applications. Known as Spring4Shell it's been in the news recently: As Mirth Connect is a JAVA application, wondering if anyone has insight into whether it's affected. I've done some initial investigation and couldn't find any direct references to the Spring framework, but finding it hard to rule out it's use. Wondering if anyone with more experience in the codebase than me can comment? Many Thanks, |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
You found the correct solution. MC does not use Spring. https://github.com/nextgenhealthcare/connect/search?q=spring&type=code |
Beta Was this translation helpful? Give feedback.
-
Also, MC uses Jetty as the container servlet. |
Beta Was this translation helpful? Give feedback.
You found the correct solution. MC does not use Spring. https://github.com/nextgenhealthcare/connect/search?q=spring&type=code