Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreCross-site scripting (XSS) vulnerability in the file upload feature of Spring Batch Admin allows a remote attacker to inject arbitrary web script or HTML via a crafted request related to the file upload functionality.
Spring Batch Admin:
This vulnerability has not been fixed as Spring Batch Admin has reached its end of life as of January 1, 2018. Spring Cloud Data Flow is the recommended replacement for managing and monitoring Spring Batch jobs going forward.
The issue was identified and responsibly reported by Wen Bin Kong.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy