Spring-security-core Vulnerability 

Issue date: 06-11-2024
Affects versions: 15.6, 14.7

Security Issue ID

SECURITY-571

 

Affected Product Version(s)

15.6.0, 14.7.21 (and previous patch releases)

 

Severity 

High

 

Description

CVE-2024-22257

In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.

CVSS v3 Base Score: N/A

CWE-862: Missing Authorization

Instructions

Customers are recommended to upgrade to the latest version. As of the time of writing, 14.7.22, 15.7.0 or 16.1.0.