Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2024-38821

Spring Security: authorization bypass for static resources in WebFlux applications

Technology

Spring Security

CVSS Score

9.1 / 10.0

Affected Versions

6.3.0 to 6.3.3; 6.2.0 to 6.2.6; 6.1.0 to 6.1.10; 6.0.0 to 6.0.12; 5.8.0 to 5.8.14; 5.7.12 and earlier

Upstream Fix

6.3.4, 6.2.7 (public); 6.1.11, 6.0.13, 5.8.15, 5.7.13 (Enterprise Support Only)

Published

October 28, 2024

OSSeva Coverage

Fixed upstream

Description

Spring Security authorization rules on static resources in Spring WebFlux applications can be bypassed under certain circumstances. An application is affected only if it is a WebFlux application, uses Spring's static resources support, and applies a non-permitAll authorization rule to that support. CVSS is VMware's score as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 6.3.0 to 6.3.3; 6.2.0 to 6.2.6; 6.1.0 to 6.1.10; 6.0.0 to 6.0.12; 5.8.0 to 5.8.14; 5.7.12 and earlier, you need this patch. Book a discovery call to get covered.