Remote Execution Flaws a Risk to Spring Framework Applications(securityweek.com)
securityweek.com
Remote Execution Flaws a Risk to Spring Framework Applications
http://www.securityweek.com/remote-execution-flaws-risk-spring-framework-applications
http://www.securityweek.com/remote-execution-flaws-risk-spring-framework-applications
I believe this is the actual advisory: http://www.mindedsecurity.com/fileshare/ExpressionLanguageIn...
It appears that spring double evaluates the expressions, so you can send a request param that is an EL expression that references values present in the server environment.