Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5771
HistoryJan 31, 2018 - 3:11 a.m.

Security Constraint Bypass

2018-01-3103:11:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.002

Percentile

55.1%

spring-security-web and spring-web are vulnerable to security bypass with static resources. Spring uses the output of getPathInfo() when mapping security constraints and requests. It is not standardized whether the path parameters should be included in the value from getPathInfo(). Using this knowledge, attackers can bypass security constraints by using encoded characters.