Описание
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
A flaw was found in Spring MVC and WebFlux. A remote attacker with low privileges could exploit this vulnerability, requiring user interaction. This could lead to stream corruption, potentially affecting the integrity of data being transmitted.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | spring-webmvc | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | spring-webmvc | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | spring-webflux | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | spring-webmvc | Fix deferred | ||
| Red Hat build of OptaPlanner 8 | spring-webmvc | Fix deferred | ||
| Red Hat Data Grid 8 | spring-webmvc | Fix deferred | ||
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Fix deferred | ||
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Fix deferred | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Fix deferred | ||
| Red Hat Enterprise Linux 9 | log4j | Fix deferred |
Показывать по
Дополнительная информация
Статус:
2.6 Low
CVSS3
Связанные уязвимости
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Spring MVC and WebFlux applications are vulnerable to stream corruptio ...
Spring MVC and WebFlux has Server Sent Event stream corruption
2.6 Low
CVSS3