Cross-Domain Request Through Insecure JSONP Defaults
Vulnerability description
spring-webmvc is vulnerable to cross-domain requests. The vulnerability exists as JSONP is enabled through the jsonp and callback JSONP parameters in MappingJackson2JsonView by default.
Veracode Software Composition Analysis
jsonp
andcallback
JSONP parameters in MappingJackson2JsonView by default.Links: