- Applications using both
spring-cloud-netflix-hystrix-dashboard
andspring-boot-starter-thymeleaf
expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at/hystrix/monitor;[user-provided data]
, the path elements followinghystrix/monitor
are being evaluated as SpringEL expressions, which can lead to code execution.