As it has been reported by pivotal yesterday (March 6th, 2018) initially reported (Sept last year) vulnerability has been corrected in latest versions of Spring Data REST and Spring Boot.
The dynamic of the growth of how many discovered vulnerabilities have been fixed recently does not inspire an optimism. Taking into account number of arbitrary code execution vulnerability calling Spring as sustainable platform might be raise some reasonable questions…