CVE-2016-5007 – org.springframework.security:spring-security-config
Package
Manager: maven
Name: org.springframework.security:spring-security-config
Vulnerable Version: >=3.2.0 <=4.2.9
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS: N/A pctlN/A
Details
Affected versions of this package are vulnerable to Authentication Bypass. The strictness of the Spring Security and the Spring Framework request mapping may differ, which could lead to resources not being secured
Metadata
Created:
Modified:
Source: MANUAL
CWE IDs: ["CWE-41"]
Alternative ID: N/A
Finding: F006
Auto approve: 1