You are not affected if you are not using @EnableMethodSecurity, or
you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7998 | Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods |
Github GHSA |
GHSA-hh3m-g4qj-4835 | Spring Security Vulnerable to Authorization Bypass via Security Annotations |
Wed, 26 Mar 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | spring-security: authorization bypass via incorrectly locating method security annotations on parameterized types or methods | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 24 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Mar 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-03-24T18:06:24.575Z
Reserved: 2025-01-02T04:29:30.445Z
Link: CVE-2025-22223
Updated: 2025-03-24T18:05:11.228Z
Status : Awaiting Analysis
Published: 2025-03-24T18:15:22.673
Modified: 2025-03-27T16:45:46.410
Link: CVE-2025-22223
OpenCVE Enrichment
No data.
EUVD
Github GHSA