Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-20860
HistoryMar 27, 2023 - 10:15 p.m.

Security feature bypass

2023-03-2722:15:00
PRIOn knowledge base
www.prio-n.com
11
spring framework
security bypass
configuration mismatch
pattern matching
potential vulnerability

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.7%

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using “**” as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.