GHSA-3h6f-g5f3-gc4w
GitHub Security Advisory
Access Control Bypass in Spring Security
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
Affected Packages
Maven
org.springframework.security:spring-security-config
Affected versions:
5.6.0
(fixed in 5.6.12)
Maven
org.springframework.security:spring-security-config
Affected versions:
5.7.0
(fixed in 5.7.10)
Maven
org.springframework.security:spring-security-config
Affected versions:
5.8.0
(fixed in 5.8.5)
Maven
org.springframework.security:spring-security-config
Affected versions:
6.0.0
(fixed in 6.0.5)
Maven
org.springframework.security:spring-security-config
Affected versions:
6.1.0
(fixed in 6.1.2)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: September 19, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.