Insecure Default Initialization of Resource in Pivotal Spring Web Flow
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
>= 2.4.0, <= 2.4.4
Patched versions
2.4.5
Description
Published by the National Vulnerability Database
Jun 13, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 1, 2022
Last updated
Jan 27, 2023
An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings.
References