Логотип exploitDog
bind:CVE-2022-22978
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-22978

Количество 6

Количество 6

ubuntu логотип

CVE-2022-22978

больше 3 лет назад

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
EPSS: Критический
redhat логотип

CVE-2022-22978

больше 3 лет назад

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2022-22978

больше 3 лет назад

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
EPSS: Критический
debian логотип

CVE-2022-22978

больше 3 лет назад

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and olde ...

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-hh32-7344-cg2f

больше 3 лет назад

Authorization bypass in Spring Security

CVSS3: 9.8
EPSS: Критический
fstec логотип

BDU:2022-04236

больше 3 лет назад

Уязвимость компонента RegexRequestMatcher Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, позволяющая нарушителю повысить свои привилегии

CVSS3: 9.8
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-22978

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
90%
Критический
больше 3 лет назад
redhat логотип
CVE-2022-22978

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
90%
Критический
больше 3 лет назад
nvd логотип
CVE-2022-22978

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
90%
Критический
больше 3 лет назад
debian логотип
CVE-2022-22978

In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and olde ...

CVSS3: 9.8
90%
Критический
больше 3 лет назад
github логотип
GHSA-hh32-7344-cg2f

Authorization bypass in Spring Security

CVSS3: 9.8
90%
Критический
больше 3 лет назад
fstec логотип
BDU:2022-04236

Уязвимость компонента RegexRequestMatcher Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, позволяющая нарушителю повысить свои привилегии

CVSS3: 9.8
90%
Критический
больше 3 лет назад

Уязвимостей на страницу