Description
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Spring / Spring Framework7.0.0 – 7.0.8
- Spring / Spring Framework6.2.0 – 6.2.19
- VMware / Spring Framework6.2.0 – 6.2.20
References
Updated 5m ago · 8 sources