In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to
5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8,
versions 6.2.x prior to 6.2.3, an application is possible vulnerable to
broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter. | In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter. |
Tue, 12 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Pivotal Software
Pivotal Software spring Security |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:pivotal_software:spring_security:5.7.0:*:*:*:*:*:*:* cpe:2.3:a:pivotal_software:spring_security:5.8.0:*:*:*:*:*:*:* cpe:2.3:a:pivotal_software:spring_security:6.0.0:*:*:*:*:*:*:* cpe:2.3:a:pivotal_software:spring_security:6.1.0:*:*:*:*:*:*:* cpe:2.3:a:pivotal_software:spring_security:6.2.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Pivotal Software
Pivotal Software spring Security |
|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-02-13T17:33:39.030Z
Reserved: 2024-01-08T18:43:15.942Z
Link: CVE-2024-22257

Updated: 2024-08-01T22:43:34.618Z

Status : Awaiting Analysis
Published: 2024-03-18T15:15:41.790
Modified: 2025-02-13T18:16:47.687
Link: CVE-2024-22257
