spring-cloud-function-web is vulnerable to HTTP Request/Response Splitting
31
Low Risk
spring-cloud-function-web can fail to filter HTTP headers correctly. Untrusted header values may then be forwarded in ways the application did not intend. That can smuggle or leak header data across a trust boundary. The patch filters headers before they are propagated.
You are affected if you are using a version that falls within the vulnerable range and Spring Cloud Function web adapters forward HTTP headers from untrusted input.
spring-cloud-function-web is vulnerable to HTTP Request/Response Splitting in versions 0.0.1 - 5.0.3.
Upgrade the org.springframework.cloud:spring-cloud-function-web library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant