Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-38810

Опубликовано: 20 авг. 2024
Источник: redhat
CVSS3: 6.5

Описание

Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.

A flaw was found in the spring-security package. Missing Authorization when using the @AuthorizeReturnObject in Spring Security allows an attacker to render security annotations ineffective.

Отчет

Applications where any of the following are true are not impacted:

  • The application is not using @PreFilter, @PostFilter, @PreAuthorize, or @PostAuthorize on any wrapped objects
  • The application is not using @EnableMethodSecurity to enable method security
  • The application is not using @AuthorizeReturnObject or the AuthorizationAdvisorProxyFactory @Bean produced by Spring Security
  • The application doesn't have any FactoryBeans
  • The application is not using AnnotationAwareAspectJAutoProxyCreator for auto-proxy creation

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2org.springframework.security/spring-security-coreNot affected
OpenShift Developer Tools and ServicesjenkinsNot affected
Red Hat build of Apache Camel for Spring Boot 3org.springframework.security/spring-security-coreNot affected
Red Hat build of Apache Camel for Spring Boot 4org.springframework.security/spring-security-coreNot affected
Red Hat build of Apache Camel - HawtIO 4org.springframework.security/spring-security-coreNot affected
Red Hat Build of Keycloakorg.springframework.security/spring-security-coreNot affected
Red Hat build of Quarkusio.quarkus.quarkus-spring-security-core-apiNot affected
Red Hat Data Grid 8org.springframework.security/spring-security-coreNot affected
Red Hat Fuse 7org.apache.servicemix.bundles/org.apache.servicemix.bundles.spring-security-coreNot affected
Red Hat Fuse 7org.springframework.security/spring-security-coreNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2305945spring-security: Missing Authorization When Using @AuthorizeReturnObject

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.

CVSS3: 6.5
nvd
больше 1 года назад

Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.

CVSS3: 6.5
debian
больше 1 года назад

Missing Authorization When Using @AuthorizeReturnObject in Spring Secu ...

CVSS3: 6.5
github
больше 1 года назад

Spring Security Missing Authorization vulnerability

6.5 Medium

CVSS3