Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreUsing "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
Spring Framework:
| Fix version | Availability |
|---|---|
| 6.0.7 | OSS |
| 5.3.26 | OSS |
No further mitigation steps are necessary.
This vulnerability was discovered internally.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy