4.0.2
5 years ago
1 months ago
Known vulnerabilities in the io.awspring.cloud:spring-cloud-aws-autoconfigure package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Missing Authentication for Critical Function in the SNS HTTP/HTTPS notification endpoints due to missing signature verification. An attacker can cause the application to process arbitrary payloads as legitimate notifications, auto-confirm subscriptions, or unsubscribe from attacker-controlled topics by sending crafted HTTP POST requests to the endpoint. How to fix Missing Authentication for Critical Function? Upgrade | [3.0.0-M1,4.0.2) |