GHSA-cxrj-66c5-9fmh
GitHub Security Advisory
Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
Affected Packages
Maven
org.springframework:spring-core
Affected versions:
5.0.5.RELEASE
(fixed in 5.0.6.RELEASE)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 7, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.