Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreWhen applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This can open up applications to various attacks including exposing sensitive data via caching mechanisms.
Spring Security:
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 5.7.21 | 5.7.22 | Enterprise Support Only |
| 5.8.23 | 5.8.24 | Enterprise Support Only |
| 6.3.14 | 6.3.15 | Enterprise Support Only |
| 6.4.14 | 6.4.15 | Enterprise Support Only |
| 6.5.8 | 6.5.9 | OSS |
| 7.0.3 | 7.0.4 | OSS |
The issue was identified and responsibly reported by Wyfrel.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy