Back to Vulnerability Directory
HIGHFixed upstream

CVE-2024-22257

Spring Security: AuthenticatedVoter returns true for a null Authentication

Technology

Spring Security

CVSS Score

8.2 / 10.0

Affected Versions

5.7.11 and earlier; 5.8.0 to 5.8.10; 6.0.0 to 6.0.9; 6.1.0 to 6.1.7; 6.2.0 to 6.2.2

Upstream Fix

5.7.12; 5.8.11; 6.1.8; 6.2.3; 6.0.10 (Enterprise Support Only)

Published

March 18, 2024

OSSeva Coverage

Fixed upstream

Description

An application that calls AuthenticatedVoter#vote directly and passes a null Authentication gets an erroneous true result, which can break access control. AuthenticatedVoter has been deprecated since 5.8 in favour of AuthorizationManager implementations. Spring Boot 2.7.18 manages Spring Security 5.7.11, which is affected. The 8.2 score is VMware's as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 5.7.11 and earlier; 5.8.0 to 5.8.10; 6.0.0 to 6.0.9; 6.1.0 to 6.1.7; 6.2.0 to 6.2.2, you need this patch. Book a discovery call to get covered.