<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Prosspa Eternal</title>
    <description>The latest articles on DEV Community by Prosspa Eternal (@prosspa_eternal).</description>
    <link>https://dev.to/prosspa_eternal</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4106839%2F967964a0-c679-4d0d-863b-3bfffc23e706.webp</url>
      <title>DEV Community: Prosspa Eternal</title>
      <link>https://dev.to/prosspa_eternal</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/prosspa_eternal"/>
    <language>en</language>
    <item>
      <title>CVE-2022-22965: Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.</title>
      <dc:creator>Prosspa Eternal</dc:creator>
      <pubDate>Wed, 02 Sep 2026 20:57:21 +0000</pubDate>
      <link>https://dev.to/prosspa_eternal/cve-2022-22965-spring-mvc-or-spring-webflux-application-running-on-jdk-9-may-be-vulnerable-to-233d</link>
      <guid>https://dev.to/prosspa_eternal/cve-2022-22965-spring-mvc-or-spring-webflux-application-running-on-jdk-9-may-be-vulnerable-to-233d</guid>
      <description>&lt;p&gt;CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The vulnerability affects versions 5.3.0 and above of Spring Framework and JDK 9 and above.&lt;/p&gt;

&lt;p&gt;The vulnerability allows an attacker to execute arbitrary code on a vulnerable Spring application running on JDK 9+ if the application is deployed as a WAR file. This could lead to unauthorized access, data theft, or system compromise.&lt;/p&gt;

&lt;p&gt;Recommended action: Upgrade to Spring Framework versions 5.2.20 or 5.3.18, or JDK versions below 9. Ensure applications are not deployed as WAR files but rather as Spring Boot executable jars.&lt;/p&gt;

&lt;p&gt;Read the verified Spring Framework brief on DevCurrent: &lt;a href="https://devcurrent.net/cve/CVE-2022-22965?utm_source=devto&amp;amp;utm_medium=community&amp;amp;utm_campaign=editorial_distribution&amp;amp;utm_content=58" rel="noopener noreferrer"&gt;https://devcurrent.net/cve/CVE-2022-22965?utm_source=devto&amp;amp;utm_medium=community&amp;amp;utm_campaign=editorial_distribution&amp;amp;utm_content=58&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://devcurrent.net/cve/CVE-2022-22965?utm_source=devto&amp;amp;utm_medium=community&amp;amp;utm_campaign=editorial_distribution&amp;amp;utm_content=58" rel="noopener noreferrer"&gt;https://devcurrent.net/cve/CVE-2022-22965?utm_source=devto&amp;amp;utm_medium=community&amp;amp;utm_campaign=editorial_distribution&amp;amp;utm_content=58&lt;/a&gt;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>CVE-2022-0543: Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.</title>
      <dc:creator>Prosspa Eternal</dc:creator>
      <pubDate>Wed, 02 Sep 2026 20:55:54 +0000</pubDate>
      <link>https://dev.to/prosspa_eternal/cve-2022-0543-redis-is-prone-to-a-debian-specific-lua-sandbox-escape-which-could-result-in-1g76</link>
      <guid>https://dev.to/prosspa_eternal/cve-2022-0543-redis-is-prone-to-a-debian-specific-lua-sandbox-escape-which-could-result-in-1g76</guid>
      <description>&lt;p&gt;CVE-2022-0543: Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.&lt;/p&gt;

&lt;p&gt;The vulnerability allows remote code execution on affected systems, posing a significant risk to both internal and external networks. It is critical to address as it can lead to unauthorized access, data theft, or system compromise.&lt;/p&gt;

&lt;p&gt;Recommended action: Apply the latest security patches from the vendor, ensure Redis is configured securely, and monitor for any suspicious activity. Follow the official advisory recommendations to mitigate the risk.&lt;/p&gt;

&lt;p&gt;Read the verified Redis brief on DevCurrent: &lt;a href="https://devcurrent.net/cve/CVE-2022-0543?utm_source=devto&amp;amp;utm_medium=community&amp;amp;utm_campaign=editorial_distribution&amp;amp;utm_content=16" rel="noopener noreferrer"&gt;https://devcurrent.net/cve/CVE-2022-0543?utm_source=devto&amp;amp;utm_medium=community&amp;amp;utm_campaign=editorial_distribution&amp;amp;utm_content=16&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://devcurrent.net/cve/CVE-2022-0543?utm_source=devto&amp;amp;utm_medium=community&amp;amp;utm_campaign=editorial_distribution&amp;amp;utm_content=16" rel="noopener noreferrer"&gt;https://devcurrent.net/cve/CVE-2022-0543?utm_source=devto&amp;amp;utm_medium=community&amp;amp;utm_campaign=editorial_distribution&amp;amp;utm_content=16&lt;/a&gt;&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>security</category>
      <category>devops</category>
      <category>node</category>
    </item>
  </channel>
</rss>
