CyberRota Analysis
AI-GeneratedWebFlux applications utilizing the Jetty 12 Core reactive adapter are vulnerable due to the serialization of response cookies lacking the sameSite attribute, which can lead to potential cross-site request forgery (CSRF) attacks. Organizations using Spring Framework versions 6.2.0 to 6.2.19 and 7.0.0 to 7.0.8 should prioritize addressing this vulnerability to enhance their application's security posture against cookie-related exploits.
Original NVD Description
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Related CVEs
Other vulnerabilities affecting the same vendor(s)