Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-41248

Опубликовано: 16 сент. 2025
Источник: redhat
CVSS3: 7.5

Описание

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4spring-security-coreAffected
Red Hat build of Apache Camel - HawtIO 4spring-security-coreAffected
Red Hat Data Grid 8spring-security-coreWill not fix
Red Hat Fuse 7spring-security-coreAffected
Red Hat JBoss Enterprise Application Platform 7spring-security-coreAffected
Red Hat JBoss Enterprise Application Platform 8spring-security-coreNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packspring-security-coreNot affected
Red Hat OpenShift Dev Spacesdevspaces/pluginregistry-rhel9Affected
Red Hat Process Automation 7spring-security-coreAffected
Red Hat Single Sign-On 7spring-security-coreAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-289
https://bugzilla.redhat.com/show_bug.cgi?id=2395723org.springframework.security/spring-security-core: Spring Security authorization bypass

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .

CVSS3: 7.5
nvd
3 месяца назад

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .

CVSS3: 7.5
debian
3 месяца назад

The Spring Security annotation detection mechanism may not correctly r ...

CVSS3: 7.5
github
3 месяца назад

Spring Security annotation detection mechanism has authorization bypass

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость функции @EnableMethodSecurity Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, позволяющая нарушителю обойти существующие механизмы безопасности

7.5 High

CVSS3