Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0586 | Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. |
Github GHSA |
GHSA-cxrj-66c5-9fmh | Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T02:56:37.459Z
Reserved: 2017-12-06T00:00:00
Link: CVE-2018-1258
No data.
Status : Modified
Published: 2018-05-11T20:29:00.260
Modified: 2024-11-21T03:59:28.953
Link: CVE-2018-1258
OpenCVE Enrichment
No data.
EUVD
Github GHSA