PT-2023-2259 · Spring+1 · Spring Security+3

CVE-2023-20860

·

Published

2023-03-20

·

Updated

2026-08-14

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Spring Framework versions 5.3.0 through 5.3.25 Spring Framework versions 6.0.0 through 6.0.6
Description The issue is related to a mismatch in pattern matching between Spring Security and Spring MVC when using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher. This can potentially lead to a security bypass. The vulnerability may allow a remote attacker to impact the integrity of protected information.
Recommendations For Spring Framework versions 5.3.0 through 5.3.25, consider updating the Spring Security configuration to avoid using "" as a pattern in the mvcRequestMatcher. For Spring Framework versions 6.0.0 through 6.0.6, consider updating the Spring Security configuration to avoid using "" as a pattern in the mvcRequestMatcher. As a temporary workaround, consider disabling the mvcRequestMatcher function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02018
CVE-2023-20860
GHSA-7PHW-CXX7-Q9VQ
RHSA-2023:3610
RHSA-2023:3622
RHSA-2023:3625
RHSA-2023:3663
RHSA-2023:3771
RHSA-2024:0778

Affected Products

Debian
Spring Framework
Spring Mvc
Spring Security