Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2023-20873

Spring Boot: security bypass for applications deployed to Cloud Foundry

Technology

Spring Boot

CVSS Score

9.8 / 10.0

Affected Versions

3.0.0 to 3.0.5; 2.7.0 to 2.7.10; 2.6.0 to 2.6.14; 2.5.14 and earlier

Upstream Fix

3.0.6; 2.7.11; 2.6.15; 2.5.15

Published

April 20, 2023

OSSeva Coverage

Fixed upstream

Description

A Spring Boot application deployed to Cloud Foundry could be susceptible to a security bypass through the Cloud Foundry actuator endpoints. Fixed in 3.0.6, 2.7.11, 2.6.15 and 2.5.15. Spring's workaround is to disable the Cloud Foundry actuator endpoints with management.cloudfoundry.enabled=false.

Upstream record: NVD · CVE.org

Is your Spring Boot deployment affected?

If you're running 3.0.0 to 3.0.5; 2.7.0 to 2.7.10; 2.6.0 to 2.6.14; 2.5.14 and earlier, you need this patch. Book a discovery call to get covered.