{"api_version":"1","generated_at":"2026-07-04T03:48:12+00:00","cve":"CVE-2024-22257","urls":{"html":"https://cve.report/CVE-2024-22257","api":"https://cve.report/api/cve/CVE-2024-22257.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2024-22257","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2024-22257"},"summary":{"title":"CVE-2024-22257","description":"In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to \n5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, \nversions 6.2.x prior to 6.2.3, an application is possible vulnerable to \nbroken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.","state":"PUBLISHED","assigner":"vmware","published_at":"2024-03-18 15:15:41","updated_at":"2026-06-30 13:16:50"},"problem_types":["CWE-862","Possible Broken Access Control in Spring Security With Direct Use of AuthenticatedVoter","CWE-862 CWE-862 Missing Authorization"],"metrics":[{"version":"3.1","source":"security@vmware.com","type":"Secondary","score":"8.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/dependency-check/DependencyCheck/issues/8642","name":"https://github.com/dependency-check/DependencyCheck/issues/8642","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://security.netapp.com/advisory/ntap-20240419-0005/","name":"https://security.netapp.com/advisory/ntap-20240419-0005/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://spring.io/security/cve-2024-22257","name":"https://spring.io/security/cve-2024-22257","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-22257","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-22257","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"N/A","product":"Spring Security","version":"affected 6.2.0 to 6.2.2, 6.1.0 to 6.1.7, 6.0.0 to 6.0.9, 5.8.0 to 5.8.10, 5.7.0 to 5.7.11","platforms":[]},{"source":"ADP","vendor":"pivotal_software","product":"spring_security","version":"affected 5.7.0 5.7.11 custom","platforms":[]},{"source":"ADP","vendor":"pivotal_software","product":"spring_security","version":"affected 5.8.0 5.8.10 custom","platforms":[]},{"source":"ADP","vendor":"pivotal_software","product":"spring_security","version":"affected 6.0.0 6.0.9 custom","platforms":[]},{"source":"ADP","vendor":"pivotal_software","product":"spring_security","version":"affected 6.1.0 6.1.7 custom","platforms":[]},{"source":"ADP","vendor":"pivotal_software","product":"spring_security","version":"affected 6.2.0 6.2.2 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2024","cve_id":"22257","cve":"CVE-2024-22257","epss":"0.009480000","percentile":"0.568380000","score_date":"2026-07-03","updated_at":"2026-07-04 00:02:19"},"legacy_qids":[{"cve":"CVE-2024-22257","qid":"997766","title":"Java (Maven) Security Update for org.springframework.security:spring-security-core (GHSA-f3jh-qvm4-mg39)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"affected":[{"cpes":["cpe:2.3:a:pivotal_software:spring_security:5.7.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:spring_security:5.8.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:spring_security:6.0.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:spring_security:6.1.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:spring_security:6.2.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","product":"spring_security","vendor":"pivotal_software","versions":[{"lessThanOrEqual":"5.7.11","status":"affected","version":"5.7.0","versionType":"custom"},{"lessThanOrEqual":"5.8.10","status":"affected","version":"5.8.0","versionType":"custom"},{"lessThanOrEqual":"6.0.9","status":"affected","version":"6.0.0","versionType":"custom"},{"lessThanOrEqual":"6.1.7","status":"affected","version":"6.1.0","versionType":"custom"},{"lessThanOrEqual":"6.2.2","status":"affected","version":"6.2.0","versionType":"custom"}]}],"metrics":[{"other":{"content":{"id":"CVE-2024-22257","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2024-11-12T15:22:14.458591Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2024-11-12T15:32:11.373Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2026-06-30T13:13:48.866Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"https://github.com/dependency-check/DependencyCheck/issues/8642"},{"tags":["x_transferred"],"url":"https://spring.io/security/cve-2024-22257"},{"tags":["x_transferred"],"url":"https://security.netapp.com/advisory/ntap-20240419-0005/"}],"title":"CVE Program Container","x_generator":{"engine":"ADPogram 0.0.1"}}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Spring Security","vendor":"N/A","versions":[{"status":"affected","version":"6.2.0 to 6.2.2, 6.1.0 to 6.1.7, 6.0.0 to 6.0.9, 5.8.0 to 5.8.10, 5.7.0 to 5.7.11"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to \n5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, \nversions 6.2.x prior to 6.2.3, an application is possible vulnerable to \nbroken access control when it directly uses the <code>AuthenticatedVoter#vote</code> passing a <code>null</code> Authentication parameter."}],"value":"In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to \n5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, \nversions 6.2.x prior to 6.2.3, an application is possible vulnerable to \nbroken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"description":"Possible Broken Access Control in Spring Security With Direct Use of AuthenticatedVoter","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2024-04-19T07:05:54.309Z","orgId":"dcf2e128-44bd-42ed-91e8-88f912c1401d","shortName":"vmware"},"references":[{"url":"https://spring.io/security/cve-2024-22257"},{"url":"https://security.netapp.com/advisory/ntap-20240419-0005/"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.1.0-dev"}}},"cveMetadata":{"assignerOrgId":"dcf2e128-44bd-42ed-91e8-88f912c1401d","assignerShortName":"vmware","cveId":"CVE-2024-22257","datePublished":"2024-03-18T14:18:52.986Z","dateReserved":"2024-01-08T18:43:15.942Z","dateUpdated":"2026-06-30T13:13:48.866Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2024-03-18 15:15:41","lastModifiedDate":"2026-06-30 13:16:50","problem_types":["CWE-862","Possible Broken Access Control in Spring Security With Direct Use of AuthenticatedVoter","CWE-862 CWE-862 Missing Authorization"],"metrics":{"cvssMetricV31":[{"source":"security@vmware.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-12T15:22:14.458591Z","id":"CVE-2024-22257","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2024","CveId":"22257","Ordinal":"1","Title":"CVE-2024-22257","CVE":"CVE-2024-22257","Year":"2024"},"notes":[{"CveYear":"2024","CveId":"22257","Ordinal":"1","NoteData":"In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to \n5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, \nversions 6.2.x prior to 6.2.3, an application is possible vulnerable to \nbroken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.","Type":"Description","Title":"CVE-2024-22257"}]}}}