Описание
Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.
A flaw was found in Spring Security. When an application uses <sec:intercept-url> to define authorization rules, the servlet path may not be correctly included in the path matcher. This oversight can lead to an authorization bypass, allowing a remote attacker to access protected resources without proper authentication or authorization.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Not affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Not affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Not affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | spring-security-core | Not affected | ||
| Red Hat build of Apache Camel - HawtIO 4 | spring-security-core | Not affected | ||
| Red Hat build of Quarkus | quarkus-spring-security-core-api | Not affected | ||
| Red Hat Data Grid 8 | spring-security-core | Not affected | ||
| Red Hat Fuse 7 | org.apache.servicemix.bundles.spring-security-core | Not affected | ||
| Red Hat Fuse 7 | spring-security-core | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | spring-security-core | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.
Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.
Vulnerability in Spring Spring Security. If an application uses<sec:in ...
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules
EPSS
7.5 High
CVSS3