CVE-2022-22978, GHSA-hh32-7344-cg2f
maven/org.springframework.security/spring-security-web
Authorization bypass in Spring Security
In Spring Security versions 5.5.6 and 5.5.7 and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with .
in the regular expression are possibly vulnerable to an authorization bypass.
All versions before 5.5.7, all versions starting from 5.6.0 before 5.6.4
Upgrade to versions 5.5.7, 5.6.4 or above.
2023-09-06
source |