Re: spring-bean RCE (indirect vulnerability of Servlet/jsp request get/post)

2022-04-01 Thread Martin Grigorov
Hi, I don't think a normal Wicket application is vulnerable to this attack. But I recommend you to update Spring in your applications anyway. On Fri, Apr 1, 2022, 10:21 kyrindorx wrote: > Hello everyone, > > The internet developer community found a bug in > spring-beans/spring-webmvc on

spring-bean RCE (indirect vulnerability of Servlet/jsp request get/post)

2022-04-01 Thread kyrindorx
Hello everyone, The internet developer community found a bug in spring-beans/spring-webmvc on 03/30/2022. I would like to know to what extent Wicket could be affected for this exploit? I think it should be a specific behavior with Spring and the servlet engine (Tomcat was used in the