Описание
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass.
You are not affected if you are not using @EnableMethodSecurity, or
you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods
A flaw was found in the Spring Security framework. In certain configurations, an authorization bypass vulnerability may be exploited due to Spring Security not correctly locating method security annotations on parameterized types or methods.
Отчет
This issue does not affect you if you are not using @EnableMethodSecurity, do not have method security annotations on parameterized types or methods, or if all method security annotations are attached to target methods.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| A-MQ Clients 2 | spring-security-core | Not affected | ||
| OpenShift Developer Tools and Services | jenkins | Not affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | spring-security-core | Not affected | ||
| Red Hat build of Quarkus | quarkus-bom | Not affected | ||
| Red Hat Data Grid 8 | spring-security-core | Not affected | ||
| Red Hat Fuse 7 | org.apache.servicemix.bundles.spring-security-core | Out of support scope | ||
| Red Hat Fuse 7 | spring-security-core | Out of support scope | ||
| Red Hat Integration Camel K 1 | spring-security-core | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | spring-security-core | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | spring-security-core | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security ...
Spring Security Vulnerable to Authorization Bypass via Security Annotations
EPSS
5.3 Medium
CVSS3