Loading HuntDB...

GHSA-gq28-h5vg-8prx

GitHub Security Advisory

Privilege escalation in spring security

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to run with elevated privileges in a small portion of the application, the bug can be leveraged to extend those privileges to the rest of the application.

Affected Packages

Maven org.springframework.security:spring-security-bom
Affected versions: 5.4.0 (fixed in 5.4.4)
Maven org.springframework.security:spring-security-bom
Affected versions: 5.3.0 (fixed in 5.3.8)
Maven org.springframework.security:spring-security-bom
Affected versions: 0 (fixed in 5.2.9)
Maven org.springframework.security:spring-security-web
Affected versions: 5.4.0 (fixed in 5.4.4)
Maven org.springframework.security:spring-security-web
Affected versions: 5.3.0 (fixed in 5.3.8)
Maven org.springframework.security:spring-security-web
Affected versions: 0 (fixed in 5.2.9)

Related CVEs

Key Information

GHSA ID
GHSA-gq28-h5vg-8prx
Published
May 10, 2021 3:22 PM
Last Modified
August 31, 2021 9:18 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.springframework.security:spring-security-bom
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 20, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.