Lucene search

K
osvGoogleOSV:GHSA-HH32-7344-CG2F
HistoryMay 20, 2022 - 12:00 a.m.

Authorization bypass in Spring Security

2022-05-2000:00:39
Google
osv.dev
59

0.009 Low

EPSS

Percentile

82.3%

In Spring Security versions 5.5.6 and 5.5.7 and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.