PT-2023-3578 · Spring · Spring Webflux

·

CVE-2023-34034

·

Published

2023-07-17

·

Updated

2024-10-28

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Spring WebFlux versions (affected versions not specified)
Description Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass. The issue may allow a remote attacker to bypass existing security restrictions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Improper Access Control

Improper Authentication

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2023-03799
BDU:2023-03800
CVE-2023-34034
GHSA-3H6F-G5F3-GC4W

Affected Products

Spring Webflux