Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass
High severity
GitHub Reviewed
Published
Oct 17, 2018
to the GitHub Advisory Database
•
Updated Mar 14, 2024
Package
Affected versions
= 5.0.5.RELEASE
Patched versions
5.0.6.RELEASE
Description
Published by the National Vulnerability Database
May 11, 2018
Published to the GitHub Advisory Database
Oct 17, 2018
Reviewed
Jun 16, 2020
Last updated
Mar 14, 2024
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
References