

























Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views.
The application must have a mapping for "/**" that results in view rendering, and where
the view name is not explicitly specified.
Spring Framework:
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 7.0.x | 7.0.6 | OSS |
| 6.2.x | 6.2.17 | OSS |
| 6.1.x | 6.1.26 | Commercial |
| 5.3.x | 5.3.47 | Commercial |
No further mitigation steps are necessary.
This vulnerability was discovered and responsibly reported by Gyu-hyeok Lee (g2h).
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。