spring-cloud-function-serverless-web is vulnerable to Incorrect Resource Transfer Between Spheres
31
Low Risk
spring-cloud-function-serverless-web ServerlessHttpServletRequest.isSecure() does not check the actual request scheme. Callers that treat isSecure() as proof of HTTPS can make the wrong access or cookie decision. That can downgrade a security check that depends on a secure transport. The patch bases isSecure() on the real scheme.
You are affected if you are using a version that falls within the vulnerable range and ServerlessHttpServletRequest.isSecure() is used to make security decisions.
spring-cloud-function-serverless-web is vulnerable to Incorrect Resource Transfer Between Spheres in versions 4.2.0 - 5.0.3.
Upgrade the org.springframework.cloud:spring-cloud-function-serverless-web library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant