{"id":"CVE-2021-22047","details":"In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.","aliases":["GHSA-4926-qpxg-6r3w"],"modified":"2026-07-09T00:12:36.121481Z","published":"2021-10-28T16:15:07.623Z","references":[{"type":"ADVISORY","url":"https://tanzu.vmware.com/security/cve-2021-22047"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/spring-projects/spring-data-rest","events":[{"introduced":"3a05cca9b6179891c6670b8c331bb11a363c0418"},{"last_affected":"86c15e63063c68878501c89a8e211c9aad07c70c"},{"introduced":"8a690929f09b3334d4af21bd338f6832d71634d0"},{"last_affected":"20fb7e6c8e038977c0ead7c13ab5cdfb15531617"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.4.0"},{"last_affected":"3.4.13"},{"introduced":"3.5.0"},{"last_affected":"3.5.5"}]}}],"versions":["3.5.5","3.4.13","3.5.4","3.4.12","3.5.3","3.4.11","3.5.2","3.4.10","3.5.1","3.4.9","3.5.0","3.4.8","3.4.7","3.4.6","3.4.5","3.4.4","3.4.3","3.4.2","3.4.1","3.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22047.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}