{"id":"CVE-2011-2732","description":"CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the spring-security-redirect parameter.","cvssScore":4.3,"cvssVersion":"2.0","cvssVector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","cvssMetrics":[{"version":"2.0","score":4.3,"vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-94"],"resolved":"MITIGATION-CANDIDATE","published":"2012-12-05","lastModified":"2026-06-16","affectedProducts":[{"vendor":"vmware","product":"springsource spring security","versionEnd":"\u003c=2.0.6"},{"vendor":"vmware","product":"springsource spring security","versionEnd":"\u003c=3.0.5"},{"vendor":"vmware","product":"springsource spring security","version":"2.0.0"},{"vendor":"vmware","product":"springsource spring security","version":"2.0.1"},{"vendor":"vmware","product":"springsource spring security","version":"2.0.2"},{"vendor":"vmware","product":"springsource spring security","version":"2.0.3"},{"vendor":"vmware","product":"springsource spring security","version":"2.0.4"},{"vendor":"vmware","product":"springsource spring security","version":"2.0.5"},{"vendor":"vmware","product":"springsource spring security","version":"3.0.0"},{"vendor":"vmware","product":"springsource spring security","version":"3.0.1"},{"vendor":"vmware","product":"springsource spring security","version":"3.0.2"},{"vendor":"vmware","product":"springsource spring security","version":"3.0.3"},{"vendor":"vmware","product":"springsource spring security","version":"3.0.4"}],"totalAffectedProducts":1,"references":[{"url":"https://github.com/spring-projects/spring-security","source":"osv","tags":["PACKAGE"]},{"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=677814","source":"osv","tags":["WEB"]},{"url":"http://support.springsource.com/security/cve-2011-2732","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"open-source-maven","decidingReason":"This CVE affects an open-source Java library published on Maven Central (Maven packages: org.springframework.security:spring-security-core), so it is squarely in ARMR's territory and the source needed to understand the defect is public. That makes it a candidate for an ARMR patch rule. No rule exists and none is scheduled: the diff between the affected and fixed versions has not been read, and a closer look may find no hook point ARMR can act on.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.springframework.security:spring-security-core"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.springframework.security:spring-security-core). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written.","decisive":true},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"withheld","detail":"Has 1 known POC(s) clearing the evidence bar — requires review despite MEDIUM severity"},{"rule":"no-exploit-published","stage":"disposition","outcome":"no-match","detail":"A KEV listing, a CISA verdict of active exploitation, or a reviewed exploit catalogue carries this CVE — somebody has published a working exploit, so it stays a candidate"}],"affectedProducts":[{"vendor":"vmware","product":"springsource_spring_security","isKnown":false,"cpe":"cpe:2.3:a:vmware:springsource_spring_security:*:*:*:*:*:*:*:*"}],"affectedPackages":[{"name":"org.springframework.security:spring-security-core","introduced":"0","fixed":"2.0.7"},{"name":"org.springframework.security:spring-security-core","introduced":"3.0.0","fixed":"3.0.6"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"inferred"}},"exploits":[{"source":"exploit-db","url":"https://www.exploit-db.com/exploits/36130","title":"Spring Security - HTTP Header Injection","date":"2011-09-09"}],"signals":{"hasPOC":true,"pocCount":1,"pocSources":["exploit-db"],"firstPOCDate":"2011-09-09"},"kev":{"inKEV":false},"epss":{"available":true,"score":0.04646,"percentile":0.91223},"ssvc":{"available":false}}