Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreIn Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution.
Spring Cloud Data Flow:
| Fix version | Availability |
|---|---|
| 2.6.5 | OSS |
| 2.5.4 | OSS |
Users should upgrade to 2.5.4 and higher.
This issue was identified and responsibly reported by Sufijen Bani from CHECK24 Factory GmbH.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy