Overview
About vulnerability
- When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.
- This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers:
-
from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
Details
- Affected product:
- Spring , cxf , logging-log4j2
- Affected packages:
- cxf @ 3.5.11 (+1832 more)
- When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.
- This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers:
-
from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.