CVE-2025-22235
Spring Boot: EndpointRequest.to() creates a matcher for null/** when the endpoint is not exposed
Technology
Spring Boot
CVSS Score
7.3 / 10.0
Affected Versions
3.4.0 to 3.4.4; 3.3.0 to 3.3.10; 3.2.0 to 3.2.13.2; 3.1.0 to 3.1.15.2; 2.7.24.2 and earlier
Upstream Fix
3.4.5, 3.3.11 (public); 3.2.14, 3.1.16, 2.7.25 (Enterprise Support Only)
Published
April 28, 2025
OSSeva Coverage
Fixed upstream
Description
EndpointRequest.to() creates a matcher for null/** if the actuator endpoint it refers to is disabled or not exposed over the web. An application is affected if it uses Spring Security, uses EndpointRequest.to() in a security chain, references an endpoint that is disabled or not exposed, and handles requests to /null that need protection. Spring's workaround is to make sure the referenced endpoint is enabled and exposed, or not to handle requests to /null. CVSS is VMware's score as the CNA.
Is your Spring Boot deployment affected?
If you're running 3.4.0 to 3.4.4; 3.3.0 to 3.3.10; 3.2.0 to 3.2.13.2; 3.1.0 to 3.1.15.2; 2.7.24.2 and earlier, you need this patch. Book a discovery call to get covered.