PT-2023-2259 · Spring+1 · Spring Security+3
CVE-2023-20860
·
Publicado
2023-03-20
·
Atualizado
2026-08-14
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Framework versions 5.3.0 through 5.3.25
Spring Framework versions 6.0.0 through 6.0.6
Description
The issue is related to a mismatch in pattern matching between Spring Security and Spring MVC when using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher. This can potentially lead to a security bypass. The vulnerability may allow a remote attacker to impact the integrity of protected information.
Recommendations
For Spring Framework versions 5.3.0 through 5.3.25, consider updating the Spring Security configuration to avoid using "" as a pattern in the mvcRequestMatcher.
For Spring Framework versions 6.0.0 through 6.0.6, consider updating the Spring Security configuration to avoid using "" as a pattern in the mvcRequestMatcher.
As a temporary workaround, consider disabling the
mvcRequestMatcher function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Protection Mechanism Failure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Debian
Spring Framework
Spring Mvc
Spring Security