CVE-2023-20860

CVSS v3.1 7.5 (High)
75% Progress
EPSS 0.09 % (41th)
0.09% Progress
Affected Products 1
Advisories 1

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.

Weaknesses
CWE-NVD-noinfo
CVE Status
PUBLISHED
CNA
VMware
Published Date
2023-03-27 22:15:21
(18 months ago)
Updated Date
2023-05-05 20:15:10
(16 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Vmware Spring Framework from 5.3.0 version and prior 5.3.26 version cpe:2.3:a:vmware:spring_framework >= 5.3.0 < 5.3.26
  Vmware Spring Framework from 6.0.0 version and prior 6.0.7 version cpe:2.3:a:vmware:spring_framework >= 6.0.0 < 6.0.7
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...