Lucene search

K
f5F5F5:K000134500
HistoryMay 08, 2023 - 12:00 a.m.

K000134500 : Spring Framework vulnerability CVE-2023-20860

2023-05-0800:00:00
my.f5.com
14
spring framework
security advisory
pattern matching
spring security
spring mvc
vulnerability
cve-2023-20860

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

36.7%

Security Advisory Description

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using “**” as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass (CVE-2023-20860).

Impact

There is no impact; F5 products are not affected by this vulnerability.