Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29909
HistoryApr 06, 2021 - 3:21 a.m.

Privilege Escalation

2021-04-0603:21:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.003 Low

EPSS

Percentile

65.8%

spring-security-web is vulnerable to privilege escalation. The SecurityContext is not saved if it has been changed more than once in a single request, allowing a malicious user to run with elevated privileges in a small portion of the application, and subsequently may extend those privileges to the rest of the application.

References

0.003 Low

EPSS

Percentile

65.8%