Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Hans Hosea Schaefer

Researcher froming.de
#50349of 56,330
5.3Total CVSS
Vulnerabilities · 1
PT-2023-24650
5.3
2023-07-17
Spring · Spring Hateoas · CVE-2023-34036
**Name of the Vulnerable Software and Affected Versions** Spring HATEOAS (affected versions not specified) **Description** Reactive web applications using Spring HATEOAS to produce hypermedia-based responses may be exposed to malicious forwarded headers if not behind a trusted proxy or without measures to handle such headers in WebFlux or the underlying HTTP server. The application is affected if it uses the reactive web stack with Spring HATEOAS and does not guard against clients submitting (X-)Forwarded headers. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.