Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings.
Affected applications are those that deserialize attacker-supplied hypermedia, for example via a @RequestBody bound to a RepresentationModel, EntityModel, or CollectionModel, or by calling Links.parse() / Link.valueOf() on a client-supplied Link header.
Spring HATEOAS:
| Fix version | Availability |
|---|---|
| 3.0.4 | OSS |
| 3.0.3.1 | Enterprise Support Only |
| 2.5.3 | OSS |
| 2.5.2.1 | Enterprise Support Only |
| 2.4.2 | Enterprise Support Only |
| 2.3.5 | Enterprise Support Only |
| 1.5.7 | Enterprise Support Only |
No further mitigation steps are necessary.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy