Overview
About vulnerability
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1.
PartEventHttpMessageReader is used when controller a method has an @RequestBody Flux<PartEvent> argument.
Details
- Affected product:
- Spring , activemq , azure-spring-data-cosmos , camel , java-sdk
- Affected packages:
- Spring Framework @ 6.2.13 (+2311 more)