QID 980285
QID 980285: Java (maven) Security Update for org.springframework:spring-core (GHSA-cxrj-66c5-9fmh)
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cxrj-66c5-9fmh for updates pertaining to this vulnerability.
Vendor References
- GHSA-cxrj-66c5-9fmh -
github.com/advisories/GHSA-cxrj-66c5-9fmh
CVEs related to QID 980285
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cxrj-66c5-9fmh | org.springframework:spring-core |
|