spring-ws-security is vulnerable to Observable Discrepancy
50
Medium Risk
Spring Web Services Security may disclose account status information through SOAP authentication responses. In certain Spring Security integration paths, detailed authentication errors such as locked or disabled account states can be exposed to remote clients instead of generic authentication failures. An attacker can leverage these differences to enumerate valid user accounts and infer account status information, aiding further attacks.
You are affected if you are using a version that falls within the vulnerable range.
spring-ws-security is vulnerable to Observable Discrepancy in versions 0.0.1 - 3.1.8, 4.0.0 - 4.0.18, 4.1.0 - 4.1.3 and 5.0.0 - 5.0.1.
Upgrade the org.springframework.ws:spring-ws-security library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant