spring-js-resources is vulnerable to Expression Language Injection
50
Medium Risk
Spring Web Flow contains an expression language injection vulnerability when applications use WebFlowELExpressionParser or ELExpressionParser without enabling Spring binding protections. In affected configurations, attackers may supply malicious Unified EL expressions that are evaluated during data binding, potentially allowing unauthorized access to application data, manipulation of application state, or execution of unintended operations.
You are affected if you are using a version that falls within the vulnerable range and you are using WebFlowELExpressionParser (or ELExpressionParser), do not enable useSpringBinding, and do not explicitly restrict bindable properties through <binding> declarations in view states.
spring-js-resources is vulnerable to Expression Language Injection in versions 0.0.1 - 2.5.1, 3.0.0 - 3.0.1 and 4.0.0 - 4.0.0.
Upgrade the org.springframework.webflow:spring-js-resources library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant