vendor:
Spring Security
by:
7.5
CVSS
HIGH
Arbitrary HTTP Header Injection
CWE
Product Name: Spring Security
Affected Version From: 2.0.0
Affected Version To: 3.0.5
Patch Exists: YES
Related CWE:
CPE: a:spring_framework:spring_security
Platforms Tested:
Arbitrary HTTP Header Injection in Spring Security
Attackers can inject arbitrary HTTP headers into an HTTP response, allowing them to launch various attacks such as cross-site request forgery, cross-site scripting, and HTTP-request smuggling.
Mitigation:
Implement input sanitization to properly sanitize user input in Spring Security.