CVE-2018-1229: Stored XSS in file upload of Spring Batch Admin
Severity
Low
Vendor
Spring by Pivotal
Description
Cross-site scripting (XSS) vulnerability in the file upload feature of Spring Batch Admin allows a remote attacker to inject arbitrary web script or HTML via a crafted request related to the file upload functionality.
Affected VMware Products and Versions
Severity is low unless otherwise noted.
- Spring Batch Admin all versions
Mitigation
Users of affected versions should apply the following mitigation:
- Spring Batch Admin has reached end of life as of January 1, 2018. Spring Cloud Data Flow is the recommended replacement for managing and monitoring Spring Batch jobs going forward.
Credit
This vulnerability was responsibly reported by Wen Bin Kong.
References
- https://docs.spring.io/spring-batch-admin
- https://github.com/spring-projects/spring-batch-admin/blob/master/MIGRATION.md
History
2018-03-16: Initial vulnerability report published.