Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreA local attacker on the same host as the application may be able to take control of the
directory used by ApplicationTemp. When server.servlet.session.persistent is set to
true and the attack persists across application restarts, this may allow the attacker
to read session information and hijack authenticated users or deploy a gadget chain and
execute code as the application's user.
Spring Boot:
Versions that are no longer supported are also affected.
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 4.0.x | 4.0.6 | OSS |
| 3.5.x | 3.5.14 | OSS |
| 3.4.x | 3.4.16 | Enterprise Support Only |
| 3.3.x | 3.3.19 | Enterprise Support Only |
| 2.7.x | 2.7.33 | Enterprise Support Only |
No further mitigation steps are necessary.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy