Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41329
HistoryJul 18, 2023 - 7:16 a.m.

Improper Neutralization Of HTTP Headers

2023-07-1807:16:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
vulnerability
http headers
spoofing
security mechanisms
reactive web stack
spring webflux

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

0.001 Low

EPSS

Percentile

30.1%

Spring HATEOS is vulnerable to Improper Neutralization Of HTTP Headers. The vulnerability is due to not sanitizing or stripping the “Forwarded”, “X-Forwarded-Host”, “X-Forwarded-Port” or “X-Forwarded-Proto” headers. This can allow an attacker to spoof these headers values thereby bypassing security mechanisms meant to prevent illegitimate access. The application needs to use reactive web stack (Spring WebFlux) for this vulnerability to materialise.

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

0.001 Low

EPSS

Percentile

30.1%

Related for VERACODE:41329