Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer.
Affected applications are those whose domain model includes an embeddable object, collection, or map property whose container is marked read-only at the Jackson level while the inner element type carries no per-field restriction.
Spring Data REST:
| Fix version | Availability |
|---|---|
| 5.0.6 | OSS |
| 5.0.5.1 | Enterprise Support Only |
| 4.5.12 | OSS |
| 4.5.11.1 | Enterprise Support Only |
| 4.4.15 | Enterprise Support Only |
| 4.3.17 | Enterprise Support Only |
| 3.7.20 | Enterprise Support Only |
No further mitigation steps are necessary.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy