FAQs

STATEMENT FROM ELEARNING BROTHERS REGARDING Spring Framework “CVE-2022-22965” VULNERABILITY

March 30, 2022

On March 29, 2022, Spring.io announced an RCE vulnerability in the Spring Framework software, reported as CVE-2022-22965.  The vulnerability impacts Spring MVC and Spring WebFlux applications running on JDK 9+. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. 

eLearning Brothers has conducted an analysis of the possible impact on all software applications we offer.  We are pleased to state that there are NO VULNERABILITIES to our software applications.  

Applications:

Account Portal - NOT VULNERABLE

Asset Library - NOT VULNERABLE

CenarioVR - NOT VULNERABLE

CourseMill - NOT VULNERABLE

Lectora Desktop - NOT VULNERABLE

Lectora Online - NOT VULNERABLE

Rehearsal - NOT VULNERABLE

ReviewLink - NOT VULNERABLE

Rockstar Learning Platform - NOT VULNERABLE

The Game Agency / The Training Arcade® - NOT VULNERABLE

If you need any further information regarding this matter, please feel free to email info@elblearning.com.

Note: Content published by Lectora or Lectora Online is NOT VULNERABLE.