The vendor explicitly identifies these products as affected by this CVE.
- resteasy-javadoc (pki-core:10.6) as a component of Red Hat Enterprise Linux 8
- resteasy-javadoc (pki-deps:10.6) as a component of Red Hat Enterprise Linux 8
- resteasy.src (pki-core:10.6) as a component of Red Hat Enterprise Linux 8
- resteasy.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux 8
- resteasy (pki-core:10.6) as a component of Red Hat Enterprise Linux 8
- resteasy (pki-deps:10.6) as a component of Red Hat Enterprise Linux 8
- pki-resteasy as a component of Red Hat Enterprise Linux 9
- pki-resteasy-client as a component of Red Hat Enterprise Linux 9
- pki-resteasy-core as a component of Red Hat Enterprise Linux 9
- pki-resteasy-jackson2-provider as a component of Red Hat Enterprise Linux 9
- pki-resteasy-servlet-initializer as a component of Red Hat Enterprise Linux 9
- spring-webmvc as a component of Red Hat Fuse 7
- Summary
- A flaw was found in Spring Framework. This vulnerability allows a header predicate bypass to occur in a pre-flight request within a WebFlux application that uses functional endpoints and is deployed with DispatcherServlet. This bypass could potentially lead to unexpected behavior or security policy circumvention.
- Remediation
- Affected
