spring-webmvc is vulnerable to Open Redirect
54
Medium Risk
spring-webmvc and spring-webflux UrlHandlerFilter can issue an open redirect when configured with overly broad URL patterns. A crafted request path is then used as the redirect location. Users following that response can be sent to an untrusted site. The patch rejects redirect targets that fall outside the intended application paths.
You are affected if you are using a version that falls within the vulnerable range and UrlHandlerFilter is configured with a very broadly matching pattern.
spring-webmvc is vulnerable to Open Redirect in versions 6.2.0 - 7.0.8.
Upgrade the org.springframework:spring-webmvc and/or the org.springframework:spring-webflux library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant