WebFlux Security Bypass With Un-Prefixed Double Wildcard Pattern

CRITICAL | JULY 18, 2023 | CVE-2023-34034

Description

Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.

Affected Spring Products and Versions

Spring Security:

  • 6.1.0 - 6.1.1
  • 6.0.0 - 6.0.4
  • 5.8.0 - 5.8.4
  • 5.7.0 - 5.7.9
  • 5.6.0 - 5.6.11

Mitigation

Users of affected versions should upgrade to the corresponding fixed version.
Fix versionAvailability
6.1.2OSS
6.0.5OSS
5.8.5OSS
5.7.10OSS
5.6.12OSS

The above require Spring Framework versions:

  • 6.0.11+
  • 5.3.29+
  • 5.2.25+

Credit

This vulnerability was disclosed responsibly by tkswifty and Ha1c9on.

History

  • 2023-07-18: Initial vulnerability report published.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all