Impact
The vulnerability is located in the PermissionService.checkUserPermission method of wxiaoqi Spring-Cloud-Platform. An attacker can manipulate the RPC request to bypass authorization logic, which is an Authorization Bypass (CWE‑862) and a Permission Check Failure (CWE‑863). The result is that remote users may access protected resources or functionalities that they should not be allowed to use. Public exploits are available, meaning the attack is feasible in real‑world scenarios.
Affected Systems
Affected systems include wxiaoqi's Spring‑Cloud‑Platform version 3.0.1 and 3.1.0. The flaw exists in the Permission Service component, specifically the PermissionService.java file. No other versions have been identified; the vulnerability is not listed in the CISA KEV catalog. If your deployment uses either of these releases, it is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is below 1%, which suggests the current likelihood of exploitation is very low, but it is not unavailable. The vulnerability is not yet listed in the KEV catalog, indicating it may not have widespread exploitation, yet publicly available proofs of concept exist. The most likely attack vector is remote exploitation via the exposed RPC PermissionService endpoint, where an attacker can send crafted requests to trigger the missing authorization check.
OpenCVE Enrichment