CVE-2023-34034
Access Control Bypass in Spring Security
Description
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
Base CVSS
9.1
EPSS Score
39.35%
Introduced Version
5.6.0
Fix Available
6.1.2,5.6.12,5.7.10,5.8.5,6.0.5
Available Patches
Package
CVEs Fixed
Lines of Code Changed