Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4926-qpxg-6r3w

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Exposure of Resource to Wrong Sphere in Spring Data REST

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.

Пакеты

Наименование

org.springframework.data:spring-data-rest-core

maven
Затронутые версииВерсия исправления

>= 3.4.0, <= 3.4.13

3.4.14

Наименование

org.springframework.data:spring-data-rest-core

maven
Затронутые версииВерсия исправления

>= 3.5.0, <= 3.5.5

3.5.6

EPSS

Процентиль: 54%
0.00315
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 5.3
nvd
больше 4 лет назад

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.

EPSS

Процентиль: 54%
0.00315
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-668