In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to
5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8,
versions 6.2.x prior to 6.2.3, an application is possible vulnerable to
broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Pivotal Software
Pivotal Software spring Security |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:pivotal_software:spring_security:5.7.0:*:*:*:*:*:*:* cpe:2.3:a:pivotal_software:spring_security:5.8.0:*:*:*:*:*:*:* cpe:2.3:a:pivotal_software:spring_security:6.0.0:*:*:*:*:*:*:* cpe:2.3:a:pivotal_software:spring_security:6.1.0:*:*:*:*:*:*:* cpe:2.3:a:pivotal_software:spring_security:6.2.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Pivotal Software
Pivotal Software spring Security |
|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: vmware
Published: 2024-03-18T14:18:52.986Z
Updated: 2024-11-12T15:32:11.373Z
Reserved: 2024-01-08T18:43:15.942Z
Link: CVE-2024-22257
Vulnrichment
Updated: 2024-08-01T22:43:34.618Z
NVD
Status : Awaiting Analysis
Published: 2024-03-18T15:15:41.790
Modified: 2024-11-21T08:55:54.403
Link: CVE-2024-22257
Redhat