Описание
Spring Web Flow has Data Binding Vulnerability with Unified EL Parser
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.
Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
Пакеты
Наименование
org.springframework.webflow:spring-webflow
maven
Затронутые версииВерсия исправления
= 4.0.0
4.0.1
Наименование
org.springframework.webflow:spring-webflow
maven
Затронутые версииВерсия исправления
>= 3.0.0, < 3.0.2
3.0.2
Наименование
org.springframework.webflow:spring-webflow
maven
Затронутые версииВерсия исправления
<= 2.5.1
Отсутствует
Связанные уязвимости
CVSS3: 6.4
nvd
2 месяца назад
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.