← Retour
CVE-2024-38821
Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
Résumé
Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
Paquets affectés
maven
org.springframework.security:spring-security-web
[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.7.13"}]}]
Références
- web https://nvd.nist.gov/vuln/detail/CVE-2024-38821
- web https://spring.io/security/cve-2024-38821
- web https://github.com/spring-projects/spring-security/commit/0e257b56ce35402558a260ffa6b368982f9a7934
- web https://github.com/spring-projects/spring-security/commit/4ce7cde15599c0447163fd46bac616e03318bf5b
- web https://security.netapp.com/advisory/ntap-20250124-0006
- web https://github.com/spring-projects/spring-security/commit/b4f27777556c157ec5689c0769322c90be984514
- web https://github.com/advisories/GHSA-c4q5-6c82-3qpw