Security Research

CVE-2023-38286 Spring Boot Admin SSTI: Thymeleaf Expression Injection to RCE

#Vulnerability Analysis#Code Audit#Web Security
CVE-2023-38286 Spring Boot Admin SSTI: Thymeleaf Expression Injection to RCE

Spring Boot Admin’s UI view layer uses Thymeleaf — but Thymeleaf prior to 3.1.0’s view name resolution allows attackers to inject SpEL expressions via request headers, and the template engine executes arbitrary Java code when parsing the view path.

Unlock to view this content.