Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7phw-cxx7-q9vq

Опубликовано: 28 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.

Пакеты

Наименование

org.springframework:spring

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.0.7

6.0.7

Наименование

org.springframework:spring

maven
Затронутые версииВерсия исправления

>= 5.3.0, < 5.3.26

5.3.26

EPSS

Процентиль: 98%
0.55534
Средний

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.

CVSS3: 7.5
redhat
около 2 лет назад

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.

CVSS3: 7.5
nvd
около 2 лет назад

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.

CVSS3: 7.5
debian
около 2 лет назад

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using ...

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость компонента mvcRequestMatche Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 98%
0.55534
Средний

9.1 Critical

CVSS3