Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-22978

Опубликовано: 16 мая 2022
Источник: redhat
CVSS3: 9.8

Описание

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.

A flaw was found in Spring Security. When using RegexRequestMatcher, an easy misconfiguration can bypass some servlet containers. Applications using RegexRequestMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2springframeworkNot affected
Red Hat build of QuarkusspringframeworkNot affected
Red Hat Data Grid 8springframeworkNot affected
Red Hat Decision Manager 7springframeworkFix deferred
Red Hat Integration Camel K 1springframeworkNot affected
Red Hat Integration Camel Quarkus 1springframeworkNot affected
Red Hat Integration Data Virtualisation OperatorspringframeworkOut of support scope
Red Hat JBoss BRMS 5springframeworkOut of support scope
Red Hat JBoss Data Grid 7springframeworkOut of support scope
Red Hat JBoss Data Virtualization 6springframeworkOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863->CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2087606springframework: Authorization Bypass in RegexRequestMatcher

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
nvd
больше 3 лет назад

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
debian
больше 3 лет назад

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and olde ...

CVSS3: 9.8
github
больше 3 лет назад

Authorization bypass in Spring Security

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость компонента RegexRequestMatcher Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, позволяющая нарушителю повысить свои привилегии

9.8 Critical

CVSS3