Improper authorization control for web services In org.springframework.security:spring-security-core
Description
Spring Security Missing Authorization vulnerability Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 6.3.2 |
Aliases
1. 2. 3. 4.
References
1.