Описание
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.
Affected versions:
Spring Framework 5.3.0 through 5.3.48.
A flaw was found in Spring WebFlux applications. This vulnerability allows for a security bypass when using the Kotlin Router DSL. An attacker could exploit this to bypass security restrictions, potentially leading to unauthorized access.
Отчет
Red Hat ships Spring WebFlux in Fuse 7. The affected version is set to AFFECTED/DEFER as the CVSS score (4.8) is below the 7.0 threshold. This flaw only affects applications using the Kotlin Router DSL.
Меры по смягчению последствий
This vulnerability only applies when using Kotlin Router DSL. Applications using Java-based routing are not affected.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | spring-webflux | Fix deferred |
Показывать по
Дополнительная информация
Статус:
4.8 Medium
CVSS3
Связанные уязвимости
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.
Spring WebFlux applications may be vulnerable to a security bypass whe ...
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
4.8 Medium
CVSS3