Skip to content

Instantly share code, notes, and snippets.

@tory-kk
Created December 22, 2023 17:20
Show Gist options
  • Save tory-kk/27e414d06b0457ef4a59ff5eee9e720f to your computer and use it in GitHub Desktop.
Save tory-kk/27e414d06b0457ef4a59ff5eee9e720f to your computer and use it in GitHub Desktop.
Spring Boot 2 + Spring Framework 5.3 500 response
$ curl -X GET 'http://localhost:8080/c:%u0020.../%u0020.../%u0020.../%u0020.../%u0020.../%u0020.../etc/passwd%23vt/test'
{"timestamp":"2023-12-22T17:19:38.077+00:00","status":500,"error":"Internal Server Error","path":"/c:%u0020.../%u0020.../%u0020.../%u0020.../%u0020.../%u0020.../etc/passwd%23vt/test"}
package com.example.demo;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
@SpringBootApplication
public class DemoApplication {
public static void main(String[] args) {
SpringApplication.run(DemoApplication.class, args);
}
}
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<groupId>com.example</groupId>
<artifactId>demo</artifactId>
<version>0.0.1-SNAPSHOT</version>
<name>demo</name>
<description>Demo project for Spring Boot</description>
<properties>
<java.version>11</java.version>
<!-- <spring.boot.version>2.7.12</spring.boot.version>-->
<spring.boot.version>2.7.18</spring.boot.version>
<maven.compiler.source>11</maven.compiler.source>
<maven.compiler.target>11</maven.compiler.target>
</properties>
<dependencies>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-web</artifactId>
<version>${spring.boot.version}</version>
<exclusions>
<!-- We don't need this transitive dependency since we use Jetty-->
<exclusion>
<groupId>org.apache.tomcat.embed</groupId>
<artifactId>tomcat-embed-core</artifactId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-jetty</artifactId>
<version>${spring.boot.version}</version>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-autoconfigure</artifactId>
<version>${spring.boot.version}</version>
</dependency>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-test</artifactId>
<version>${spring.boot.version}</version>
<scope>test</scope>
</dependency>
</dependencies>
<build>
<plugins>
<plugin>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-maven-plugin</artifactId>
</plugin>
</plugins>
</build>
</project>
package com.example.demo;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;
@RestController
public class TestController {
@GetMapping("/")
public ResponseEntity<?> hello() {
return ResponseEntity.ok(null);
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment