PT-2023-2259 · Spring+1 · Spring Security+3
CVE-2023-20860
·
Published
2023-03-20
·
Updated
2026-08-14
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Framework versions 5.3.0 through 5.3.25
Spring Framework versions 6.0.0 through 6.0.6
Description
The issue is related to a mismatch in pattern matching between Spring Security and Spring MVC when using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher. This can potentially lead to a security bypass. The vulnerability may allow a remote attacker to impact the integrity of protected information.
Recommendations
For Spring Framework versions 5.3.0 through 5.3.25, consider updating the Spring Security configuration to avoid using "" as a pattern in the mvcRequestMatcher.
For Spring Framework versions 6.0.0 through 6.0.6, consider updating the Spring Security configuration to avoid using "" as a pattern in the mvcRequestMatcher.
As a temporary workaround, consider disabling the
mvcRequestMatcher function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Spring Framework
Spring Mvc
Spring Security