Описание
Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components will not be exercised as intended by the application. This can lead to the authentication, authorization, and other security controls being rendered inactive on intended requests.This issue affects Spring Security: from 7.0.0 through 7.0.4.
A flaw was found in Spring Security. When an application uses specific configurations involving securityMatchers(String) and PathPatternRequestMatcher.Builder to handle servlet paths, the intended security controls may not be applied. This can result in a security bypass, where authentication and authorization mechanisms are rendered inactive, potentially allowing an attacker to gain unauthorized access or perform actions without proper validation.
Меры по смягчению последствий
Applications using Spring Security should review their configurations to ensure that securityMatchers(String) and PathPatternRequestMatcher.Builder are correctly implemented to prevent unintended security bypasses. Avoid configurations that prepend a servlet path using PathPatternRequestMatcher.Builder in conjunction with securityMatchers(String) if not explicitly required and thoroughly validated. Consult Spring Security documentation for best practices regarding servlet path matching and security filter chain configuration.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Fix deferred | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Fix deferred | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | spring-security-core | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | spring-security-core | Fix deferred | ||
| Red Hat build of Quarkus | quarkus-spring-security-core-api | Fix deferred | ||
| Red Hat Data Grid 8 | spring-security-core | Fix deferred | ||
| Red Hat Fuse 7 | org.apache.servicemix.bundles.spring-security-core | Fix deferred | ||
| Red Hat Fuse 7 | spring-security-core | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | spring-security-core | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components will not be exercised as intended by the application. This can lead to the authentication, authorization, and other security controls being rendered inactive on intended requests.This issue affects Spring Security: from 7.0.0 through 7.0.4.
Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components will not be exercised as intended by the application. This can lead to the authentication, authorization, and other security controls being rendered inactive on intended requests.This issue affects Spring Security: from 7.0.0 through 7.0.4.
Vulnerability in Spring Spring Security. If an application is usingsec ...
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers
EPSS
6.5 Medium
CVSS3