Authentication mechanism absence or evasion In org.springframework.security:spring-security-core
Description
Affected versions of this package are vulnerable to Authentication Bypass. The strictness of the Spring Security and the Spring Framework request mapping may differ, which could lead to resources not being secured
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 4.1.1 | ||
debian 12 | 4.3.2-1 | ||
debian 11 | 4.3.2-1 | ||
debian 14 | 4.3.2-1 | ||
maven | 4.3.1 | ||
debian 13 | 4.3.2-1 | ||
maven | - | ||
maven | - | ||
maven | - |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6. 7.