{"id":"GHSA-3h6f-g5f3-gc4w","summary":"Access Control Bypass in Spring Security","details":"Using \"**\" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.\n\n","aliases":["CVE-2023-34034"],"modified":"2024-10-28T19:33:10.794744Z","published":"2023-07-19T15:30:26Z","database_specific":{"cwe_ids":["CWE-281","CWE-284"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-07-31T21:19:15Z","nvd_published_at":"2023-07-19T15:15:11Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34034"},{"type":"WEB","url":"https://ossindex.sonatype.org/vulnerability/CVE-2023-34034"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230814-0008"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-5777893"},{"type":"WEB","url":"https://spring.io/security/cve-2023-34034"}],"affected":[{"package":{"name":"org.springframework.security:spring-security-config","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-config"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.6.0"},{"fixed":"5.6.12"}]}],"versions":["5.6.0","5.6.1","5.6.10","5.6.11","5.6.2","5.6.3","5.6.4","5.6.5","5.6.6","5.6.7","5.6.8","5.6.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-3h6f-g5f3-gc4w/GHSA-3h6f-g5f3-gc4w.json"}},{"package":{"name":"org.springframework.security:spring-security-config","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-config"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.7.0"},{"fixed":"5.7.10"}]}],"versions":["5.7.0","5.7.1","5.7.2","5.7.3","5.7.4","5.7.5","5.7.6","5.7.7","5.7.8","5.7.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-3h6f-g5f3-gc4w/GHSA-3h6f-g5f3-gc4w.json"}},{"package":{"name":"org.springframework.security:spring-security-config","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-config"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.8.0"},{"fixed":"5.8.5"}]}],"versions":["5.8.0","5.8.1","5.8.2","5.8.3","5.8.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-3h6f-g5f3-gc4w/GHSA-3h6f-g5f3-gc4w.json"}},{"package":{"name":"org.springframework.security:spring-security-config","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-config"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.0.5"}]}],"versions":["6.0.0","6.0.1","6.0.2","6.0.3","6.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-3h6f-g5f3-gc4w/GHSA-3h6f-g5f3-gc4w.json"}},{"package":{"name":"org.springframework.security:spring-security-config","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-config"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.1.0"},{"fixed":"6.1.2"}]}],"versions":["6.1.0","6.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-3h6f-g5f3-gc4w/GHSA-3h6f-g5f3-gc4w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}