Lucene search

K
springRob WinchSPRING:D910A9047EA53BB42480F75D9C5916E5
HistoryMay 16, 2022 - 5:27 a.m.

CVE-2022-22978: Authorization Bypass in RegexRequestMatcher

2022-05-1605:27:00
Rob Winch
spring.io
398

0.009 Low

EPSS

Percentile

82.3%

UPDATES

  • [05-17] Due to a mixup CVE-2022-22975 should have been CVE-2022-22978. The blog has been updated to reflect this correction.

CVE-2022-22978 : Authorization Bypass in RegexRequestMatcher

Spring Security 5.7.0, 5.6.4, 5.5.7 were released to fix CVE-2022-22978 : Authorization Bypass in RegexRequestMatcher. Please update as soon as possible.