Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39984
HistoryMar 30, 2023 - 2:11 a.m.

Security Bypass

2023-03-3002:11:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21
spring-webmvc
security bypass
pattern matching

0.001 Low

EPSS

Percentile

36.7%

spring-webmvc is vulnerable to Security Bypass. The vulnerability exists because using “**” as a pattern in spring security configuration with the mvcRequestMatcher which creates a mismatch in pattern matching between Spring Security and Spring MVC and the potential for a security bypass.