Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45937
HistoryMar 19, 2024 - 4:37 p.m.

Improper Access Control

2024-03-1916:37:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21
improper access control
authentication bypass
org.springframework.security
access control vulnerability

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%

org.springframework.security: spring-security-core is vulnerable to Authentication Bypass. The vulnerability is due to the isFullyAuthenticated method within the AuthenticatedVoter class incorrectly returning true if the authentication parameter is null, resulting in broken access control. Note that applications are only vulnerable if the AuthenticatedVoter.vote() method is used directly.

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%