Impact
The vulnerability arises when Spring Security serializes WebAuthn session data to a distributed store. An attacker who can modify the serialized payload can inject alternate authentication state, causing the system to accept the session without performing user verification. This results in a full authentication bypass, allowing unauthorized access to protected resources.
Affected Systems
Spring Security 7.1.0, 7.0.0 through 7.0.6, 6.5.0 through 6.5.11, and 6.4.0 through 6.4.18 are affected. All applications that use Spring Security’s WebAuthn support with a distributed HTTP session store are impacted.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, suggesting exploitation may not yet be widely observed, though the attack vector—remote manipulation of distributed session data—is likely feasible for attackers with moderate access. The documented impact is authentication bypass.
OpenCVE Enrichment