logo

CVE-2016-5007 org.springframework.security:spring-security-web

Package

Manager: maven
Name: org.springframework.security:spring-security-web
Vulnerable Version: >=3.2.0 <=4.2.9

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

EPSS: N/A pctlN/A

Details

Affected versions of this package are vulnerable to Authentication Bypass. The strictness of the Spring Security and the Spring Framework request mapping may differ, which could lead to resources not being secured

Metadata

Created:
Modified:
Source: MANUAL
CWE IDs: ["CWE-41"]
Alternative ID: N/A
Finding: F006
Auto approve: 1