Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4374
HistoryJun 06, 2017 - 3:27 a.m.

Data Binding Expression Vulnerability

2017-06-0603:27:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.259 Low

EPSS

Percentile

96.7%

Spring Web Flow is vulnerable to a data binding expression vulnerability. The vulnerability is possible because the MvcViewFactoryCreator useSpringBinding property is set to false by default. Therefore, the applications which use the default settings are vulnerable to malicious EL expressions in view states, allowing form submissions from setting fields on the target object that should not be set.

CPENameOperatorVersion
spring web flowle2.4.4.RELEASE