Improper Control of Generation of Code ('Code Injection') in Spring Framework
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Mar 14, 2024
Package
Affected versions
>= 2.5.0, <= 2.5.6
>= 3.0.0, <= 3.0.2
Patched versions
2.5.7
3.0.3
Description
Published by the National Vulnerability Database
Jun 21, 2010
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Jun 17, 2022
Last updated
Mar 14, 2024
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing
class.classLoader.URLs[0]=jar:
followed by a URL of a crafted .jar file.References