Description
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- Spring / Spring Framework7.0.0 – 7.0.5
- Spring / Spring Framework6.2.0 – 6.2.16
- Spring / Spring Framework6.1.0 – 6.1.25
- Spring / Spring Framework5.3.0 – 5.3.46
References
Updated 28m ago · 8 sources