Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreMalicious PATCH requests submitted to servers using Spring Data REST backed HTTP resources can use specially crafted JSON data to run arbitrary Java code.
Users of affected versions should apply the following mitigation:
This vulnerability was responsibly reported by Man Yue Mo from Semmle and lgtm.com.
2017-09-21: Initial vulnerability report published
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy