Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mf92-479x-3373

Опубликовано: 20 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Spring Security HTTP Headers Are not Written Under Some Conditions

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

Пакеты

Наименование

org.springframework.security:spring-security-web

maven
Затронутые версииВерсия исправления

<= 5.7.14

Отсутствует

Наименование

org.springframework.security:spring-security-web

maven
Затронутые версииВерсия исправления

>= 5.8.0, <= 5.8.16

Отсутствует

Наименование

org.springframework.security:spring-security-web

maven
Затронутые версииВерсия исправления

>= 6.0.0, <= 6.3.10

Отсутствует

Наименование

org.springframework.security:spring-security-web

maven
Затронутые версииВерсия исправления

>= 6.4.0, <= 6.4.13

Отсутствует

Наименование

org.springframework.security:spring-security-web

maven
Затронутые версииВерсия исправления

>= 6.5.0, < 6.5.9

6.5.9

Наименование

org.springframework.security:spring-security-web

maven
Затронутые версииВерсия исправления

>= 7.0.0, < 7.0.4

7.0.4

EPSS

Процентиль: 39%
0.0048
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-425

Связанные уязвимости

CVSS3: 6.5
redhat
5 месяцев назад

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

CVSS3: 9.1
nvd
5 месяцев назад

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

CVSS3: 9.1
debian
5 месяцев назад

When applications specify HTTP response headers for servlet applicatio ...

CVSS3: 9.1
fstec
5 месяцев назад

Уязвимость Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, связанная с использованием небезопасной прямой ссылкой на объект, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 39%
0.0048
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-425