Логотип exploitDog
bind:CVE-2025-41248
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-41248

Количество 6

Количество 6

ubuntu логотип

CVE-2025-41248

3 месяца назад

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-41248

3 месяца назад

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-41248

3 месяца назад

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-41248

3 месяца назад

The Spring Security annotation detection mechanism may not correctly r ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8v5q-rhf3-jphm

3 месяца назад

Spring Security annotation detection mechanism has authorization bypass

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2025-11287

3 месяца назад

Уязвимость функции @EnableMethodSecurity Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, позволяющая нарушителю обойти существующие механизмы безопасности

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-41248

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .

CVSS3: 7.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-41248

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-41248

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .

CVSS3: 7.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-41248

The Spring Security annotation detection mechanism may not correctly r ...

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-8v5q-rhf3-jphm

Spring Security annotation detection mechanism has authorization bypass

CVSS3: 7.5
0%
Низкий
3 месяца назад
fstec логотип
BDU:2025-11287

Уязвимость функции @EnableMethodSecurity Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, позволяющая нарушителю обойти существующие механизмы безопасности

CVSS3: 7.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу