Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hh3m-g4qj-4835

Опубликовано: 24 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Spring Security Vulnerable to Authorization Bypass via Security Annotations

Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. 

You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods

Пакеты

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 6.4.0, < 6.4.4

6.4.4

EPSS

Процентиль: 7%
0.00029
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 5.3
redhat
9 месяцев назад

Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass.  You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods

CVSS3: 5.3
nvd
9 месяцев назад

Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass.  You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods

CVSS3: 5.3
debian
9 месяцев назад

Spring Security 6.4.0 - 6.4.3 may not correctly locate method security ...

EPSS

Процентиль: 7%
0.00029
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-290