Skip to content

[GHSA-wg35-8jpf-2xv3] Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.#7862

Open
yuki-matsuhashi wants to merge 1 commit into
yuki-matsuhashi/advisory-improvement-7862from
yuki-matsuhashi-GHSA-wg35-8jpf-2xv3
Open

[GHSA-wg35-8jpf-2xv3] Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.#7862
yuki-matsuhashi wants to merge 1 commit into
yuki-matsuhashi/advisory-improvement-7862from
yuki-matsuhashi-GHSA-wg35-8jpf-2xv3

Conversation

@yuki-matsuhashi
Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3

Comments
The CVE record was initially published with a CVSS vector that differed from the vendor advisory and was later corrected. NVD now reflects it, while this advisory still appears to use the earlier value. This updates A:N to A:L to align with the current CVSS vector.

@github-actions github-actions Bot changed the base branch from main to yuki-matsuhashi/advisory-improvement-7862 May 31, 2026 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant