Skip to content

Commit 74e6600

Browse files
committed
Bump in Spring version to address CVE and fixed null checks in query string
1 parent 5b068e0 commit 74e6600

File tree

2 files changed

+5
-5
lines changed

2 files changed

+5
-5
lines changed

aws-serverless-java-container-core/src/main/java/com/amazonaws/serverless/proxy/internal/servlet/AwsProxyHttpServletRequest.java

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -812,11 +812,11 @@ public static String decodeValueIfEncoded(String value) {
812812

813813

814814
private String getQueryParamValue(String key, boolean isCaseSensitive) {
815-
if (isCaseSensitive) {
816-
return request.getQueryStringParameters().get(key);
817-
}
818-
819815
if (request.getQueryStringParameters() != null) {
816+
if (isCaseSensitive) {
817+
return request.getQueryStringParameters().get(key);
818+
}
819+
820820
for (String k : request.getQueryStringParameters().keySet()) {
821821
if (k.toLowerCase(Locale.getDefault()).equals(key.toLowerCase(Locale.getDefault()))) {
822822
return request.getQueryStringParameters().get(k);

aws-serverless-java-container-spring/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@
1515
</parent>
1616

1717
<properties>
18-
<spring.version>5.0.3.RELEASE</spring.version>
18+
<spring.version>5.0.7.RELEASE</spring.version>
1919
<spring-security.version>5.0.1.RELEASE</spring-security.version>
2020
<jackson.version>2.9.5</jackson.version>
2121
</properties>

0 commit comments

Comments
 (0)