Описание
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
A flaw was found in Spring Framework. In this vulnerability, a security bypass is possible due to the behavior of the wildcard pattern.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
A-MQ Clients 2 | springframework | Not affected | ||
Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel8 | Not affected | ||
Migration Toolkit for Applications 6 | org.keycloak-keycloak-parent | Not affected | ||
Migration Toolkit for Runtimes | org.keycloak-keycloak-parent | Not affected | ||
Red Hat Data Grid 8 | springframework | Not affected | ||
Red Hat Enterprise Linux 8 | log4j:2/log4j | Not affected | ||
Red Hat Enterprise Linux 9 | log4j | Not affected | ||
Red Hat Integration Camel K 1 | springframework | Not affected | ||
Red Hat Integration Camel Quarkus 1 | springframework | Not affected | ||
Red Hat JBoss Data Grid 7 | springframework | Out of support scope |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using ...
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
Уязвимость компонента mvcRequestMatche Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
7.5 High
CVSS3