Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2023-20873
Spring Boot: security bypass for applications deployed to Cloud Foundry
Technology
Spring Boot
CVSS Score
9.8 / 10.0
Affected Versions
3.0.0 to 3.0.5; 2.7.0 to 2.7.10; 2.6.0 to 2.6.14; 2.5.14 and earlier
Upstream Fix
3.0.6; 2.7.11; 2.6.15; 2.5.15
Published
April 20, 2023
OSSeva Coverage
Fixed upstream
Description
A Spring Boot application deployed to Cloud Foundry could be susceptible to a security bypass through the Cloud Foundry actuator endpoints. Fixed in 3.0.6, 2.7.11, 2.6.15 and 2.5.15. Spring's workaround is to disable the Cloud Foundry actuator endpoints with management.cloudfoundry.enabled=false.
Is your Spring Boot deployment affected?
If you're running 3.0.0 to 3.0.5; 2.7.0 to 2.7.10; 2.6.0 to 2.6.14; 2.5.14 and earlier, you need this patch. Book a discovery call to get covered.