GHSA-mf92-479x-3373
Spring Security HTTP Headers Are not Written Under Some Conditions
Quick fix
GHSA-mf92-479x-3373 — org.springframework.security:spring-security-web: upgrade to the fixed version with the command below.
# pom.xml: bump <version>6.5.9</version> for org.springframework.security:spring-security-webDetails
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for org.springframework.security:spring-security-web (maven). Pin to a known-safe version or switch to an alternative.
5.8.0No fixed version published yet for org.springframework.security:spring-security-web (maven). Pin to a known-safe version or switch to an alternative.
6.0.0No fixed version published yet for org.springframework.security:spring-security-web (maven). Pin to a known-safe version or switch to an alternative.
6.4.0No fixed version published yet for org.springframework.security:spring-security-web (maven). Pin to a known-safe version or switch to an alternative.
6.5.0Fixed in: 6.5.9# pom.xml: bump <version>6.5.9</version> for org.springframework.security:spring-security-web7.0.0Fixed in: 7.0.4# pom.xml: bump <version>7.0.4</version> for org.springframework.security:spring-security-web