Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2025-41232

Spring Security: method security annotations on private methods not enforced in AspectJ mode

Technology

Spring Security

CVSS Score

9.1 / 10.0

Affected Versions

6.4.0 to 6.4.5

Upstream Fix

6.4.6

Published

May 21, 2025

OSSeva Coverage

Fixed upstream

Description

With @EnableMethodSecurity(mode=ASPECTJ) and spring-security-aspects, Spring Security may not find method security annotations on private methods, so those methods can be invoked without the intended authorization. Applications not using AspectJ mode are not affected. The 9.1 score is VMware's as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 6.4.0 to 6.4.5, you need this patch. Book a discovery call to get covered.