Spring HATEOAS vulnerable to Improper Neutralization of HTTP Headers for Scripting Syntax
Moderate severity
GitHub Reviewed
Published
Jul 17, 2023
to the GitHub Advisory Database
•
Updated Nov 6, 2023
Package
Affected versions
< 1.5.5
>= 2.0.0, < 2.0.5
>= 2.1.0, < 2.1.1
Patched versions
1.5.5
2.0.5
2.1.1
Description
Published by the National Vulnerability Database
Jul 17, 2023
Published to the GitHub Advisory Database
Jul 17, 2023
Reviewed
Jul 17, 2023
Last updated
Nov 6, 2023
Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious forwarded headers if they are not behind a trusted proxy that ensures correctness of such headers, or if they don't have anything else in place to handle (and possibly discard) forwarded headers either in WebFlux or at the level of the underlying HTTP server.
For the application to be affected, it needs to satisfy the following requirements:
References