Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2025-41232
Spring Security: method security annotations on private methods not enforced in AspectJ mode
Technology
Spring Security
CVSS Score
9.1 / 10.0
Affected Versions
6.4.0 to 6.4.5
Upstream Fix
6.4.6
Published
May 21, 2025
OSSeva Coverage
Fixed upstream
Description
With @EnableMethodSecurity(mode=ASPECTJ) and spring-security-aspects, Spring Security may not find method security annotations on private methods, so those methods can be invoked without the intended authorization. Applications not using AspectJ mode are not affected. The 9.1 score is VMware's as the CNA.
Is your Spring Security deployment affected?
If you're running 6.4.0 to 6.4.5, you need this patch. Book a discovery call to get covered.