How lgtm Discovered the Spring Framework Vulnerability

Security researchers at lgtm.com are urging users of the Pivotal Spring framework to upgrade to the latest version due to a critical remote code execution vulnerability. The vulnerability allows attackers to execute arbitrary commands on any machine that runs an application built using Spring Data REST. The company characterizes the upgrade as “a matter of urgency.” The Spring Data REST component is distributed as part of various other Spring projects, including the Spring Boot framework.

Read full news article on The New Stack