Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreUse of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views.
The application must have a mapping for "/**" that results in view rendering, and where
the view name is not explicitly specified.
Spring Framework:
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 7.0.x | 7.0.6 | OSS |
| 6.2.x | 6.2.17 | OSS |
| 6.1.x | 6.1.26 | Commercial |
| 5.3.x | 5.3.47 | Commercial |
No further mitigation steps are necessary.
This vulnerability was discovered and responsibly reported by Gyu-hyeok Lee (g2h).
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy