Loading HuntDB...

GHSA-3h6f-g5f3-gc4w

GitHub Security Advisory

Access Control Bypass in Spring Security

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.

Affected Packages

Maven org.springframework.security:spring-security-config
Affected versions: 5.6.0 (fixed in 5.6.12)
Maven org.springframework.security:spring-security-config
Affected versions: 5.7.0 (fixed in 5.7.10)
Maven org.springframework.security:spring-security-config
Affected versions: 5.8.0 (fixed in 5.8.5)
Maven org.springframework.security:spring-security-config
Affected versions: 6.0.0 (fixed in 6.0.5)
Maven org.springframework.security:spring-security-config
Affected versions: 6.1.0 (fixed in 6.1.2)

Related CVEs

Key Information

GHSA ID
GHSA-3h6f-g5f3-gc4w
Published
July 19, 2023 3:30 PM
Last Modified
October 28, 2024 7:30 PM
CVSS Score
9.0 /10
Primary Ecosystem
Maven
Primary Package
org.springframework.security:spring-security-config
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 19, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.