Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreApplications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.
Pre-conditions:
WebFlowELExpressionParser or its base class "ELExpressionParser".useSpringBinding configuration property has not been set to true.<binding> element on a view state to declare the properties to bind.Spring Web Flow:
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 4.0.x | 4.0.1 | OSS |
| 4.0.0.1 | Enterprise Support Only | |
| 3.0.x | 3.0.2 | OSS |
| 3.0.1.1 | Enterprise Support Only | |
| 2.5.x | 2.5.2 | Enterprise Support Only |
No further mitigation steps are necessary.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy