Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v8j-3hxp-93wr

Опубликовано: 28 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Spring Boot's default security filter chain has no authorization rule with Actuator but without Health

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.

Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

Пакеты

Наименование

org.springframework.boot:spring-boot

maven
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.6

4.0.6

EPSS

Процентиль: 39%
0.00489
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.1
redhat
4 месяца назад

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

CVSS3: 9.1
nvd
4 месяца назад

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

EPSS

Процентиль: 39%
0.00489
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-862