CVE-2018-1229: Stored XSS in file upload of Spring Batch Admin

LOW | MARCH 16, 2018 | CVE-2018-1229

Description

Cross-site scripting (XSS) vulnerability in the file upload feature of Spring Batch Admin allows a remote attacker to inject arbitrary web script or HTML via a crafted request related to the file upload functionality.

Affected Spring Products and Versions

Spring Batch Admin:

  • 1.0.0.RELEASE - 1.2.1.RELEASE

Mitigation

This vulnerability has not been fixed as Spring Batch Admin has reached its end of life as of January 1, 2018. Spring Cloud Data Flow is the recommended replacement for managing and monitoring Spring Batch jobs going forward.

Credit

The issue was identified and responsibly reported by Wen Bin Kong.

References

History

  • 2018-03-16: Initial vulnerability report published.
  • 2026-07-09: Formatting improvements.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all