Impact
A flaw in Annotation Processing within LogNet grpc‑spring‑boot‑starter allows an attacker to manipulate the component in a way that bypasses the application’s established authorization controls. This weakness corresponds to CWE‑266 and CWE‑285. The public disclosure and remote exploitation potential mean that, if a suitable vector is identified, an adversary could gain unauthorized access to privileged functions or data. The vulnerability requires a high complexity level and is considered difficult to exploit, but the fact that it has already been disclosed publicly raises the risk of future exploitation attempts once a viable attack path is discovered.
Affected Systems
LogNet grpc‑spring‑boot‑starter versions up to 5.2.0 are affected. This conclusion is drawn from the vendor’s release notes and issue tracker; no other LogNet components have been identified as vulnerable by the vendor, based on the information supplied by the CNA and the absence of additional affected products listed in the CNA data.
Risk and Exploitability
With a CVSS score of 2.3, the overall severity is low. The EPSS score is not available, inferred from the lack of a published EPSS value in the assessment data. The vulnerability is not listed in CISA’s KEV catalog, an inference from the KEV field value. The attack requires remote access and high complexity, making it difficult for attackers to weaponize; however, its public disclosure raises the possibility that malicious actors may attempt to exploit it once a suitable vector is discovered.
OpenCVE Enrichment