Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker.
Pre-conditions:
Spring Web Flow:
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 4.0.x | 4.0.1 | OSS |
| 4.0.0.1 | Enterprise Support Only | |
| 3.0.x | 3.0.2 | OSS |
| 3.0.1.1 | Enterprise Support Only | |
| 2.5.x | 2.5.2 | Enterprise Support Only |
No further mitigation steps are necessary.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy