CVE-2024-38821
Spring Security: authorization bypass for static resources in WebFlux applications
Technology
Spring Security
CVSS Score
9.1 / 10.0
Affected Versions
6.3.0 to 6.3.3; 6.2.0 to 6.2.6; 6.1.0 to 6.1.10; 6.0.0 to 6.0.12; 5.8.0 to 5.8.14; 5.7.12 and earlier
Upstream Fix
6.3.4, 6.2.7 (public); 6.1.11, 6.0.13, 5.8.15, 5.7.13 (Enterprise Support Only)
Published
October 28, 2024
OSSeva Coverage
Fixed upstream
Description
Spring Security authorization rules on static resources in Spring WebFlux applications can be bypassed under certain circumstances. An application is affected only if it is a WebFlux application, uses Spring's static resources support, and applies a non-permitAll authorization rule to that support. CVSS is VMware's score as the CNA.
Is your Spring Security deployment affected?
If you're running 6.3.0 to 6.3.3; 6.2.0 to 6.2.6; 6.1.0 to 6.1.10; 6.0.0 to 6.0.12; 5.8.0 to 5.8.14; 5.7.12 and earlier, you need this patch. Book a discovery call to get covered.