A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HVMware Spring Framework
APPVmware5.2.5 – 5.2.26 (excl.)5.3.0 – 5.3.50 (excl.)6.0.0 – 6.0.31 (excl.)6.1.0 – 6.1.29 (excl.)6.2.0 – 6.2.20 (excl.)7.0.0 – 7.0.8.1 (excl.)
Related vulnerabilities
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enfo...
Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be ...
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) wi...
Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Serv...