CVE-2017-4971: Data Binding Expression Vulnerability
(updated )
Applications that do not change the value of the MvcViewFactoryCreator
useSpringBinding
property which is disabled by default (i.e.
, set to false
) can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings.
References
Detect and mitigate CVE-2017-4971 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →