Description
CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the spring-security-redirect parameter.
Remediation
References
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=677814
http://support.springsource.com/security/cve-2011-2732
Related Vulnerabilities
CVE-2019-20365 Vulnerability in maven package org.igniterealtime.openfire:xmppserver
CVE-2023-45818 Vulnerability in maven package org.webjars.npm:tinymce
CVE-2019-1003069 Vulnerability in maven package org.jenkins-ci.plugins:aqua-security-scanner
CVE-2020-24582 Vulnerability in npm package zulip
CVE-2019-1003083 Vulnerability in maven package org.jenkins-ci.plugins:gearman-plugin