Lucene search

K
cveVmwareCVE-2021-22047
HistoryOct 28, 2021 - 4:15 p.m.

CVE-2021-22047

2021-10-2816:15:07
CWE-200
CWE-668
vmware
web.nvd.nist.gov
71
cve-2021-22047
spring data rest
http resources
unauthorized access
spring security configuration
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

36.2%

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.

Affected configurations

Nvd
Node
vmwarespring_data_restRange3.4.03.4.13
OR
vmwarespring_data_restRange3.5.03.5.5
VendorProductVersionCPE
vmwarespring_data_rest*cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Spring Data REST",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Spring Data REST versions 3.4.x  prior to 3.4.14+ ,3.5.x prior to 3.5.6+ and old unsupported versions"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

36.2%