Rusty Deaton
Articles
-
December 2025 Apache Log4J2 Vulnerability FAQ
Why did we take our current approach to the December 2025 Apache Log4J vulnerability? CVE-2025-68161 details a vulnerability within Apache Log4J2, a popular logging library. The vulnerability is, ...
-
December 2024 Spring Databinder FAQ
Why did we take our current approach to CVE-2024-38820? CVE-2024-38820 details a path traversal vulnerability in Spring. Per Spring’s advisory on the matter(https://spring.io/security/cve-2024-388...
-
December 2024 Spring Path Traversal FAQ
Why did we take our current approach to CVE-2024-38819? CVE-2024-38819 details a path traversal vulnerability in Spring. Per Spring’s advisory on the matter(https://spring.io/security/cve-2024-388...
-
November 2024 Spring WebFlux FAQ (CVE-2024-38821)
CVE-2024-38821 FAQ Why did we take our current approach to CVE-2024-38821? CVE-2024-38821 details an authorization bypass of static resources in WebFlux applications. Per Spring’s advisory on the ...