Security controls bypass or absence In org.springframework:spring
Description
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 6.0.7, 5.3.26 | ||
debian 11 | - | ||
debian 12 | - | ||
debian 13 | - | ||
debian 14 | - | ||
maven | 6.0.7, 5.3.26 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4.