Spring Security Headers included, still getting 'Header Not Set' vulnerability warning

Aki T

I want to get rid of Header related vulnerability warnings. (Missing X-Frame Header, Missing Content Type Header)

I went through the Spring doc and made the required changes. But still getting those warnings (I'm using Owasap Zap security tool to validate vulnerability warnings)


<?xml version="1.0" encoding="UTF-8"?>
<beans xmlns="http://www.springframework.org/schema/beans"

    <security:http create-session="never"  entry-point-ref="http403EntryPoint" >


                <security:user name="_" password="_" authorities="_" />

    <bean id="http403EntryPoint" class="org.springframework.security.web.authentication.Http403ForbiddenEntryPoint">


I've added the required dependencies in the pom file.

   <version 4.1.0.RELEASE</version>

Aki T

I was missing the required servlet filter in the web.xml


This filter invokes a Spring bean (springSecurityFilterChain) which is an internal infrastructure bean created by the namespace to handle web security.

