spring-webmvc is vulnerable to Improper Neutralization of Special Elements
26
Low Risk
spring-webmvc functional SSE responses can be corrupted when streamed data contains event-framing characters. An attacker who influences another user's plain-text SSE payload can inject events or misleading content. JSON or other structured event formats are less affected. The patch encodes SSE data so user content cannot break the stream.
You are affected if you are using a version that falls within the vulnerable range and Spring MVC functional ServerResponse.sse() streams plain-text data that an attacker can influence for other users.
spring-webmvc is vulnerable to Improper Neutralization of Special Elements in versions 5.3.0 - 7.0.8.
Upgrade the org.springframework:spring-webmvc library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant