CVE-2024-22257
Spring Security: AuthenticatedVoter returns true for a null Authentication
Technology
Spring Security
CVSS Score
8.2 / 10.0
Affected Versions
5.7.11 and earlier; 5.8.0 to 5.8.10; 6.0.0 to 6.0.9; 6.1.0 to 6.1.7; 6.2.0 to 6.2.2
Upstream Fix
5.7.12; 5.8.11; 6.1.8; 6.2.3; 6.0.10 (Enterprise Support Only)
Published
March 18, 2024
OSSeva Coverage
Fixed upstream
Description
An application that calls AuthenticatedVoter#vote directly and passes a null Authentication gets an erroneous true result, which can break access control. AuthenticatedVoter has been deprecated since 5.8 in favour of AuthorizationManager implementations. Spring Boot 2.7.18 manages Spring Security 5.7.11, which is affected. The 8.2 score is VMware's as the CNA.
Is your Spring Security deployment affected?
If you're running 5.7.11 and earlier; 5.8.0 to 5.8.10; 6.0.0 to 6.0.9; 6.1.0 to 6.1.7; 6.2.0 to 6.2.2, you need this patch. Book a discovery call to get covered.