Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreApplications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.6.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes.
Workarounds: If the resources exposed by Spring Data REST do not need to support HTTP PATCH requests, you can disable that support as described here. Applications that have generally disabled HTTP PATCH support, either through the corresponding configuration of Spring Data REST, Spring Boot or through their runtime infrastructure, are not affected, either.
Spring Data REST:
| Fix version | Availability |
|---|---|
| 3.7.3 | OSS |
| 3.6.7 | OSS |
No further mitigation steps are necessary.
This vulnerability was initially discovered and responsibly reported by 白帽酱 @burpheart.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy