Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29397
HistoryFeb 15, 2021 - 6:52 a.m.

Authorization Bypass

2021-02-1506:52:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
authorization
bypass
vulnerable
sensitive headers
spring security
stricthttpfirewall

EPSS

0.001

Percentile

35.9%

spring-cloud-netflix-zuul is vulnerable to authorization bypass. An attacker is able to send a request containing a malicious URL to bypass the “Sensitive Headers” restrictions. Applications using Spring Security’s StrictHttpFirewall (enabled by default for all URLs) are not affected by this vulnerability.

EPSS

0.001

Percentile

35.9%

Related for VERACODE:29397