Show plain JSON{"dataType": "CVE_RECORD", "containers": {"adp": [{"title": "CVE Program Container", "references": [{"url": "https://spring.io/security/cve-2024-22257", "tags": ["x_transferred"]}, {"url": "https://security.netapp.com/advisory/ntap-20240419-0005/", "tags": ["x_transferred"]}], "providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-01T22:43:34.618Z"}}, {"title": "CISA ADP Vulnrichment", "metrics": [{"other": {"type": "ssvc", "content": {"id": "CVE-2024-22257", "role": "CISA Coordinator", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "version": "2.0.3", "timestamp": "2024-11-12T15:22:14.458591Z"}}}], "affected": [{"cpes": ["cpe:2.3:a:pivotal_software:spring_security:5.7.0:*:*:*:*:*:*:*", "cpe:2.3:a:pivotal_software:spring_security:5.8.0:*:*:*:*:*:*:*", "cpe:2.3:a:pivotal_software:spring_security:6.0.0:*:*:*:*:*:*:*", "cpe:2.3:a:pivotal_software:spring_security:6.1.0:*:*:*:*:*:*:*", "cpe:2.3:a:pivotal_software:spring_security:6.2.0:*:*:*:*:*:*:*"], "vendor": "pivotal_software", "product": "spring_security", "versions": [{"status": "affected", "version": "5.7.0", "versionType": "custom", "lessThanOrEqual": "5.7.11"}, {"status": "affected", "version": "5.8.0", "versionType": "custom", "lessThanOrEqual": "5.8.10"}, {"status": "affected", "version": "6.0.0", "versionType": "custom", "lessThanOrEqual": "6.0.9"}, {"status": "affected", "version": "6.1.0", "versionType": "custom", "lessThanOrEqual": "6.1.7"}, {"status": "affected", "version": "6.2.0", "versionType": "custom", "lessThanOrEqual": "6.2.2"}], "defaultStatus": "unknown"}], "problemTypes": [{"descriptions": [{"lang": "en", "type": "CWE", "cweId": "CWE-862", "description": "CWE-862 Missing Authorization"}]}], "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-05-23T19:01:18.409Z"}}], "cna": {"source": {"discovery": "UNKNOWN"}, "metrics": [{"format": "CVSS", "cvssV3_1": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 8.2, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "scenarios": [{"lang": "en", "value": "GENERAL"}]}], "affected": [{"vendor": "N/A", "product": "Spring Security", "versions": [{"status": "affected", "version": "6.2.0 to 6.2.2, 6.1.0 to 6.1.7, 6.0.0 to 6.0.9, 5.8.0 to 5.8.10, 5.7.0 to 5.7.11"}], "defaultStatus": "unaffected"}], "references": [{"url": "https://spring.io/security/cve-2024-22257"}, {"url": "https://security.netapp.com/advisory/ntap-20240419-0005/"}], "x_generator": {"engine": "Vulnogram 0.1.0-dev"}, "descriptions": [{"lang": "en", "value": "In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to \n5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, \nversions 6.2.x prior to 6.2.3, an application is possible vulnerable to \nbroken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.\n\n", "supportingMedia": [{"type": "text/html", "value": "\nIn Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to \n5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, \nversions 6.2.x prior to 6.2.3, an application is possible vulnerable to \nbroken access control when it directly uses the <code>AuthenticatedVoter#vote</code> passing a <code>null</code> Authentication parameter.\n\n", "base64": false}]}], "problemTypes": [{"descriptions": [{"lang": "en", "description": "Possible Broken Access Control in Spring Security With Direct Use of AuthenticatedVoter"}]}], "providerMetadata": {"orgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d", "shortName": "vmware", "dateUpdated": "2024-03-18T14:18:52.986Z"}}}, "cveMetadata": {"cveId": "CVE-2024-22257", "state": "PUBLISHED", "dateUpdated": "2024-11-12T15:32:11.373Z", "dateReserved": "2024-01-08T18:43:15.942Z", "assignerOrgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d", "datePublished": "2024-03-18T14:18:52.986Z", "assignerShortName": "vmware"}, "dataVersion": "5.1"}