Sensitive information sent insecurely In org.springframework.data:spring-data-rest-core
Description
Affected versions of this package are vulnerable to Information Exposure. HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 3.4.14, 3.5.6 | ||
maven | - |
Aliases
1. 2. 3. 4. 5.
References
1.