{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22732.json"
      }
    ],
    "title": "Spring Security: Spring Security: Security policy bypass and information disclosure due to unwritten HTTP headers",
    "tracking": {
      "current_release_date": "2026-06-28T07:17:44+00:00",
      "generator": {
        "date": "2026-06-28T07:17:44+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.2.6"
        }
      },
      "id": "CVE-2026-22732",
      "initial_release_date": "2026-03-19T22:47:38.199000+00:00",
      "revision_history": [
        {
          "date": "2026-03-19T22:47:38.199000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-04-02T08:01:25+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-28T07:17:44+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "OpenShift Developer Tools and Services",
                "product": {
                  "name": "OpenShift Developer Tools and Services",
                  "product_id": "openshift_developer_tools_and_services",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:ocp_tools"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "OpenShift Developer Tools and Services"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat build of Apache Camel for Spring Boot 4",
                "product": {
                  "name": "Red Hat build of Apache Camel for Spring Boot 4",
                  "product_id": "red_hat_build_of_apache_camel_for_spring_boot_4",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:camel_spring_boot:4"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat build of Apache Camel for Spring Boot 4"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat build of Apache Camel - HawtIO 4",
                "product": {
                  "name": "Red Hat build of Apache Camel - HawtIO 4",
                  "product_id": "red_hat_build_of_apache_camel_-_hawtio_4",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:apache_camel_hawtio:4"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat build of Apache Camel - HawtIO 4"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat build of Quarkus",
                "product": {
                  "name": "Red Hat build of Quarkus",
                  "product_id": "red_hat_build_of_quarkus",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:quarkus:3"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat build of Quarkus"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Data Grid 8",
                "product": {
                  "name": "Red Hat Data Grid 8",
                  "product_id": "red_hat_data_grid_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_data_grid:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Data Grid 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Fuse 7",
                "product": {
                  "name": "Red Hat Fuse 7",
                  "product_id": "red_hat_fuse_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_fuse:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Fuse 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 7",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 7",
                  "product_id": "red_hat_jboss_enterprise_application_platform_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 8",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 8",
                  "product_id": "red_hat_jboss_enterprise_application_platform_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                  "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jbosseapxp"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift Dev Spaces",
                "product": {
                  "name": "Red Hat OpenShift Dev Spaces",
                  "product_id": "red_hat_openshift_dev_spaces",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_devspaces:3"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift Dev Spaces"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Process Automation 7",
                "product": {
                  "name": "Red Hat Process Automation 7",
                  "product_id": "red_hat_process_automation_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Process Automation 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Single Sign-On 7",
                "product": {
                  "name": "Red Hat Single Sign-On 7",
                  "product_id": "red_hat_single_sign-on_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Single Sign-On 7"
          },
          {
            "category": "product_version",
            "name": "jenkins.src",
            "product": {
              "name": "jenkins.src",
              "product_id": "jenkins.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/jenkins?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ocp-tools-4/jenkins-rhel8",
            "product": {
              "name": "ocp-tools-4/jenkins-rhel8",
              "product_id": "ocp-tools-4/jenkins-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/jenkins-rhel8?repository_url=registry.redhat.io/ocp-tools-4/jenkins-rhel8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ocp-tools-4/jenkins-rhel9",
            "product": {
              "name": "ocp-tools-4/jenkins-rhel9",
              "product_id": "ocp-tools-4/jenkins-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/jenkins-rhel9?repository_url=registry.redhat.io/ocp-tools-4/jenkins-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "spring-security-core",
            "product": {
              "name": "spring-security-core",
              "product_id": "spring-security-core",
              "product_identification_helper": {
                "purl": "pkg:maven/org.springframework.security/spring-security-core"
              }
            }
          },
          {
            "category": "product_version",
            "name": "quarkus-spring-security-core-api",
            "product": {
              "name": "quarkus-spring-security-core-api",
              "product_id": "quarkus-spring-security-core-api",
              "product_identification_helper": {
                "purl": "pkg:maven/io.quarkus/quarkus-spring-security-core-api"
              }
            }
          },
          {
            "category": "product_version",
            "name": "org.apache.servicemix.bundles.spring-security-core",
            "product": {
              "name": "org.apache.servicemix.bundles.spring-security-core",
              "product_id": "org.apache.servicemix.bundles.spring-security-core",
              "product_identification_helper": {
                "purl": "pkg:maven/org.apache.servicemix.bundles/org.apache.servicemix.bundles.spring-security-core"
              }
            }
          },
          {
            "category": "product_version",
            "name": "devspaces/openvsx-rhel9",
            "product": {
              "name": "devspaces/openvsx-rhel9",
              "product_id": "devspaces/openvsx-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/openvsx-rhel9?repository_url=registry.redhat.io/devspaces/openvsx-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "devspaces/pluginregistry-rhel9",
            "product": {
              "name": "devspaces/pluginregistry-rhel9",
              "product_id": "devspaces/pluginregistry-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/pluginregistry-rhel9?repository_url=registry.redhat.io/devspaces/pluginregistry-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Developer Tools and Services",
          "product_id": "openshift_developer_tools_and_services:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift_developer_tools_and_services"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ocp-tools-4/jenkins-rhel8 as a component of OpenShift Developer Tools and Services",
          "product_id": "openshift_developer_tools_and_services:ocp-tools-4/jenkins-rhel8"
        },
        "product_reference": "ocp-tools-4/jenkins-rhel8",
        "relates_to_product_reference": "openshift_developer_tools_and_services"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ocp-tools-4/jenkins-rhel9 as a component of OpenShift Developer Tools and Services",
          "product_id": "openshift_developer_tools_and_services:ocp-tools-4/jenkins-rhel9"
        },
        "product_reference": "ocp-tools-4/jenkins-rhel9",
        "relates_to_product_reference": "openshift_developer_tools_and_services"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "spring-security-core as a component of Red Hat build of Apache Camel - HawtIO 4",
          "product_id": "red_hat_build_of_apache_camel_-_hawtio_4:spring-security-core"
        },
        "product_reference": "spring-security-core",
        "relates_to_product_reference": "red_hat_build_of_apache_camel_-_hawtio_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "spring-security-core as a component of Red Hat build of Apache Camel for Spring Boot 4",
          "product_id": "red_hat_build_of_apache_camel_for_spring_boot_4:spring-security-core"
        },
        "product_reference": "spring-security-core",
        "relates_to_product_reference": "red_hat_build_of_apache_camel_for_spring_boot_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "quarkus-spring-security-core-api as a component of Red Hat build of Quarkus",
          "product_id": "red_hat_build_of_quarkus:quarkus-spring-security-core-api"
        },
        "product_reference": "quarkus-spring-security-core-api",
        "relates_to_product_reference": "red_hat_build_of_quarkus"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "spring-security-core as a component of Red Hat Data Grid 8",
          "product_id": "red_hat_data_grid_8:spring-security-core"
        },
        "product_reference": "spring-security-core",
        "relates_to_product_reference": "red_hat_data_grid_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "org.apache.servicemix.bundles.spring-security-core as a component of Red Hat Fuse 7",
          "product_id": "red_hat_fuse_7:org.apache.servicemix.bundles.spring-security-core"
        },
        "product_reference": "org.apache.servicemix.bundles.spring-security-core",
        "relates_to_product_reference": "red_hat_fuse_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "spring-security-core as a component of Red Hat Fuse 7",
          "product_id": "red_hat_fuse_7:spring-security-core"
        },
        "product_reference": "spring-security-core",
        "relates_to_product_reference": "red_hat_fuse_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "spring-security-core as a component of Red Hat JBoss Enterprise Application Platform 7",
          "product_id": "red_hat_jboss_enterprise_application_platform_7:spring-security-core"
        },
        "product_reference": "spring-security-core",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "quarkus-spring-security-core-api as a component of Red Hat JBoss Enterprise Application Platform 8",
          "product_id": "red_hat_jboss_enterprise_application_platform_8:quarkus-spring-security-core-api"
        },
        "product_reference": "quarkus-spring-security-core-api",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "spring-security-core as a component of Red Hat JBoss Enterprise Application Platform 8",
          "product_id": "red_hat_jboss_enterprise_application_platform_8:spring-security-core"
        },
        "product_reference": "spring-security-core",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "quarkus-spring-security-core-api as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack:quarkus-spring-security-core-api"
        },
        "product_reference": "quarkus-spring-security-core-api",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_expansion_pack"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "spring-security-core as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack:spring-security-core"
        },
        "product_reference": "spring-security-core",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_expansion_pack"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "devspaces/openvsx-rhel9 as a component of Red Hat OpenShift Dev Spaces",
          "product_id": "red_hat_openshift_dev_spaces:devspaces/openvsx-rhel9"
        },
        "product_reference": "devspaces/openvsx-rhel9",
        "relates_to_product_reference": "red_hat_openshift_dev_spaces"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "devspaces/pluginregistry-rhel9 as a component of Red Hat OpenShift Dev Spaces",
          "product_id": "red_hat_openshift_dev_spaces:devspaces/pluginregistry-rhel9"
        },
        "product_reference": "devspaces/pluginregistry-rhel9",
        "relates_to_product_reference": "red_hat_openshift_dev_spaces"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "spring-security-core as a component of Red Hat Process Automation 7",
          "product_id": "red_hat_process_automation_7:spring-security-core"
        },
        "product_reference": "spring-security-core",
        "relates_to_product_reference": "red_hat_process_automation_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "spring-security-core as a component of Red Hat Single Sign-On 7",
          "product_id": "red_hat_single_sign-on_7:spring-security-core"
        },
        "product_reference": "spring-security-core",
        "relates_to_product_reference": "red_hat_single_sign-on_7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-22732",
      "cwe": {
        "id": "CWE-166",
        "name": "Improper Handling of Missing Special Element"
      },
      "discovery_date": "2026-03-19T23:04:17.293238+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2449306"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Spring Security. When applications using Spring Security specify HTTP response headers for servlet applications, these headers may not be written. This can lead to a bypass of security policies or information disclosure, potentially allowing an attacker to gain unauthorized access to sensitive data or compromise the integrity of the application.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "Spring Security: Spring Security: Security policy bypass and information disclosure due to unwritten HTTP headers",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "openshift_developer_tools_and_services:jenkins.src",
          "openshift_developer_tools_and_services:ocp-tools-4/jenkins-rhel8",
          "openshift_developer_tools_and_services:ocp-tools-4/jenkins-rhel9",
          "red_hat_build_of_apache_camel_-_hawtio_4:spring-security-core",
          "red_hat_build_of_apache_camel_for_spring_boot_4:spring-security-core",
          "red_hat_build_of_quarkus:quarkus-spring-security-core-api",
          "red_hat_data_grid_8:spring-security-core",
          "red_hat_fuse_7:org.apache.servicemix.bundles.spring-security-core",
          "red_hat_fuse_7:spring-security-core",
          "red_hat_jboss_enterprise_application_platform_7:spring-security-core",
          "red_hat_jboss_enterprise_application_platform_8:quarkus-spring-security-core-api",
          "red_hat_jboss_enterprise_application_platform_8:spring-security-core",
          "red_hat_jboss_enterprise_application_platform_expansion_pack:quarkus-spring-security-core-api",
          "red_hat_jboss_enterprise_application_platform_expansion_pack:spring-security-core",
          "red_hat_openshift_dev_spaces:devspaces/openvsx-rhel9",
          "red_hat_openshift_dev_spaces:devspaces/pluginregistry-rhel9",
          "red_hat_process_automation_7:spring-security-core",
          "red_hat_single_sign-on_7:spring-security-core"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-22732"
        },
        {
          "category": "external",
          "summary": "RHBZ#2449306",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2449306"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-22732",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-22732"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-22732",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
        },
        {
          "category": "external",
          "summary": "https://spring.io/security/cve-2026-22732",
          "url": "https://spring.io/security/cve-2026-22732"
        }
      ],
      "release_date": "2026-03-19T22:47:38.199000+00:00",
      "remediations": [
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "openshift_developer_tools_and_services:jenkins.src",
            "openshift_developer_tools_and_services:ocp-tools-4/jenkins-rhel8",
            "openshift_developer_tools_and_services:ocp-tools-4/jenkins-rhel9",
            "red_hat_build_of_apache_camel_-_hawtio_4:spring-security-core",
            "red_hat_build_of_apache_camel_for_spring_boot_4:spring-security-core",
            "red_hat_build_of_quarkus:quarkus-spring-security-core-api",
            "red_hat_data_grid_8:spring-security-core",
            "red_hat_fuse_7:org.apache.servicemix.bundles.spring-security-core",
            "red_hat_fuse_7:spring-security-core",
            "red_hat_jboss_enterprise_application_platform_7:spring-security-core",
            "red_hat_jboss_enterprise_application_platform_8:quarkus-spring-security-core-api",
            "red_hat_jboss_enterprise_application_platform_8:spring-security-core",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:quarkus-spring-security-core-api",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:spring-security-core",
            "red_hat_openshift_dev_spaces:devspaces/openvsx-rhel9",
            "red_hat_openshift_dev_spaces:devspaces/pluginregistry-rhel9",
            "red_hat_process_automation_7:spring-security-core",
            "red_hat_single_sign-on_7:spring-security-core"
          ]
        },
        {
          "category": "none_available",
          "details": "Fix deferred",
          "product_ids": [
            "openshift_developer_tools_and_services:jenkins.src",
            "openshift_developer_tools_and_services:ocp-tools-4/jenkins-rhel8",
            "openshift_developer_tools_and_services:ocp-tools-4/jenkins-rhel9",
            "red_hat_build_of_apache_camel_-_hawtio_4:spring-security-core",
            "red_hat_build_of_apache_camel_for_spring_boot_4:spring-security-core",
            "red_hat_build_of_quarkus:quarkus-spring-security-core-api",
            "red_hat_data_grid_8:spring-security-core",
            "red_hat_fuse_7:org.apache.servicemix.bundles.spring-security-core",
            "red_hat_fuse_7:spring-security-core",
            "red_hat_jboss_enterprise_application_platform_7:spring-security-core",
            "red_hat_jboss_enterprise_application_platform_8:quarkus-spring-security-core-api",
            "red_hat_jboss_enterprise_application_platform_8:spring-security-core",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:quarkus-spring-security-core-api",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:spring-security-core",
            "red_hat_openshift_dev_spaces:devspaces/openvsx-rhel9",
            "red_hat_openshift_dev_spaces:devspaces/pluginregistry-rhel9",
            "red_hat_process_automation_7:spring-security-core",
            "red_hat_single_sign-on_7:spring-security-core"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "openshift_developer_tools_and_services:jenkins.src",
            "openshift_developer_tools_and_services:ocp-tools-4/jenkins-rhel8",
            "openshift_developer_tools_and_services:ocp-tools-4/jenkins-rhel9",
            "red_hat_build_of_apache_camel_-_hawtio_4:spring-security-core",
            "red_hat_build_of_apache_camel_for_spring_boot_4:spring-security-core",
            "red_hat_build_of_quarkus:quarkus-spring-security-core-api",
            "red_hat_data_grid_8:spring-security-core",
            "red_hat_fuse_7:org.apache.servicemix.bundles.spring-security-core",
            "red_hat_fuse_7:spring-security-core",
            "red_hat_jboss_enterprise_application_platform_7:spring-security-core",
            "red_hat_jboss_enterprise_application_platform_8:quarkus-spring-security-core-api",
            "red_hat_jboss_enterprise_application_platform_8:spring-security-core",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:quarkus-spring-security-core-api",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:spring-security-core",
            "red_hat_openshift_dev_spaces:devspaces/openvsx-rhel9",
            "red_hat_openshift_dev_spaces:devspaces/pluginregistry-rhel9",
            "red_hat_process_automation_7:spring-security-core",
            "red_hat_single_sign-on_7:spring-security-core"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "openshift_developer_tools_and_services:jenkins.src",
            "openshift_developer_tools_and_services:ocp-tools-4/jenkins-rhel8",
            "openshift_developer_tools_and_services:ocp-tools-4/jenkins-rhel9",
            "red_hat_build_of_apache_camel_-_hawtio_4:spring-security-core",
            "red_hat_build_of_apache_camel_for_spring_boot_4:spring-security-core",
            "red_hat_build_of_quarkus:quarkus-spring-security-core-api",
            "red_hat_data_grid_8:spring-security-core",
            "red_hat_fuse_7:org.apache.servicemix.bundles.spring-security-core",
            "red_hat_fuse_7:spring-security-core",
            "red_hat_jboss_enterprise_application_platform_7:spring-security-core",
            "red_hat_jboss_enterprise_application_platform_8:quarkus-spring-security-core-api",
            "red_hat_jboss_enterprise_application_platform_8:spring-security-core",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:quarkus-spring-security-core-api",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:spring-security-core",
            "red_hat_openshift_dev_spaces:devspaces/openvsx-rhel9",
            "red_hat_openshift_dev_spaces:devspaces/pluginregistry-rhel9",
            "red_hat_process_automation_7:spring-security-core",
            "red_hat_single_sign-on_7:spring-security-core"
          ]
        }
      ],
      "title": "Spring Security: Spring Security: Security policy bypass and information disclosure due to unwritten HTTP headers"
    }
  ]
}