Impact
Spring Cloud Function suffers from inadequate filtering of HTTP headers, which may allow attackers to inject or manipulate headers in outgoing responses. The vulnerability could enable header injection attacks, but the description does not specify the exact security consequences; it is inferred that downstream vulnerabilities such as HTTP response splitting or information disclosure could result.
Affected Systems
Users deploying Spring Cloud Function version 5.0.0 through 5.0.3, 4.3.0 through 4.3.4, 4.2.0 through 4.2.7, or 3.2.16 and earlier are affected.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity. EPSS is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote exploitation via crafted HTTP requests sent to affected function endpoints, allowing attackers to inject or manipulate response headers.
OpenCVE Enrichment