Spring Security Advisories

Authorization Bypass of Static Resources in WebFlux Applications

MEDIUM | OCTOBER 22, 2024 | CVE-2024-38821

Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances.

For this to impact an application, all of the following must be true:

  • It must be a WebFlux application
  • It must be using Spring's static resources support
  • It must have a non-permitAll authorization rule applied to the static resources support

CVE-2024-38810: Missing Authorization When Using @AuthorizeReturnObject

HIGH | AUGUST 19, 2024 | CVE-2024-38810

Applications using @AuthorizeReturnObject or the Spring Security produced AuthorizationAdvisorProxyFactory @Bean to wrap objects may not have all security advice applied.

When method security advice is not applied, it means that annotations like @PreFilter and @PreAuthorize may take no affect…

CVE-2024-38808: Spring Expression DoS Vulnerability

MEDIUM | AUGUST 14, 2024 | CVE-2024-38808

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition.

Specifically, an…

CVE-2024-22271: Spring Cloud Function Web DOS Vulnerability

MEDIUM | JUNE 19, 2024 | CVE-2024-22271

Description In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions.

Specifically, an application is…

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all