← Retour
CVE-2026-47835
high
CVSS 8.6
Vulnérabilité dans CVE-2026-47835 (CVE-2026-47835)
Résumé
vulnérabilité dans CVE-2026-47835 (CVE-2026-47835). Des informations confidentielles peuvent être exposées.
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2026-47835** a été découverte dans CVE-2026-47835.
Des informations confidentielles peuvent être exposées. Score CVSS : 8.6/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « CVE-2026-47835 CVE-2026-47835 » sur le site de l'éditeur.
CVE-2026-47835 (CVE-2026-47835) — CWE-943 / CVSS v3 8.6
Vecteur d'attaque : distant (réseau) / non authentifié / sans interaction utilisateur
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
Spring AI Vector Storesにおける特別な文字による任意のクエリ実行の脆弱性。
📍 Périmètre concerné
spring-ai-elasticsearch-store、spring-ai-opensearch-store、spring-ai-gemfire-store。
🔥 Gravité
脆弱性はCVSSスコア8.6の高リスクとされ、攻撃者が任意のクエリを実行できる可能性があるため。
🔧 Comment corriger
バージョン1.0.9または1.1.8へアップデートする。
🛡️ Contournement
情報なし
🔍 Détection
パッチ未適用の影響範囲を確認するために、バージョンを確認する。
Actions de réponse (7 étapes)
Étapes concrètes et exemples de commandes que les équipes SOC/SRE doivent exécuter dans l'ordre
-
1Identify exposure identify
Audit SBOM/dependencies for affected components.依存マニフェストで影響コンポーネントを特定する。
-
7Post-deployment verification verify
Confirm patched version is live in productionパッチ適用後、ステージングで PoC または同等の悪用パターンを再現して脆弱性が閉じたことを確認。本番では Step 3 と同じログクエリでアラート再発が無いか継続監視。
Paquets affectés
maven
org.springframework.ai:spring-ai-opensearch-store
[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.8"}]}]
maven
org.springframework.ai:spring-ai-elasticsearch-store
[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.8"}]}]
maven
org.springframework.ai:spring-ai-gemfire-store
[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.8"}]}]
Références
- web https://spring.io/security/cve-2026-47835
- web https://nvd.nist.gov/vuln/detail/CVE-2026-47835
- web https://github.com/advisories/GHSA-cmwh-w62w-r2mf
- web https://github.com/spring-projects/spring-ai/commit/2b20cfc8f478444f942d4be7a867d254441ff991
- web https://github.com/spring-projects/spring-ai/commit/9787991aa1ed92c511131ddf4e142bd94051e6e7
- web https://github.com/spring-projects/spring-ai/releases/tag/v1.0.9
- web https://github.com/spring-projects/spring-ai/releases/tag/v1.1.8