Uploaded image for project: 'Common Controller SDK'
  1. Common Controller SDK
  2. CCSDK-1813

Disable http compression for external requests

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Medium Medium
    • Montreal Release
    • El Alto Release
    • cds

      spring-security-web (all versions) are vulnerable to a BREACH attack. The workaround for this issue is to disable http compression for external requests.

      Details of the attack and the workaround may be found at : https://github.com/spring-projects/spring-security/pull/4002#issuecomment-239827460

            ym9479 ym9479
            djtimoney Dan Timoney
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: