LWN.net Logo

libspring-2.5-java: information disclosure

Package(s):libspring-2.5-java CVE #(s):CVE-2011-2730
Created:June 29, 2012 Updated:August 20, 2012
Description:

From the Debian advisory:

It was discovered that the Spring Framework contains an information disclosure vulnerability in the processing of certain Expression Language (EL) patterns, allowing attackers to access sensitive information using HTTP requests.

Alerts:
Debian DSA-2504-1 2012-06-28
Mageia MGASA-2012-0217 2012-08-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds