Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreApplications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e. set to “false”) can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a
Users of affected versions should apply the following mitigation:
The issue was identified by Stefano Ciccone of Gotham Digital Science
2017-05-31: Initial vulnerability report published
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy