Site icon TheCyberThrone

Spring Security fixes Critical Vulnerability CVE-2024-38821

Advertisements

Spring Security has disclosed a critical vulnerability impacting WebFlux applications, enables an authorization bypass under specific conditions. If exploited, this vulnerability could potentially allow unauthorized access to static resources, undermining application security.

The vulnerability tracked as CVE-2024-38821 with a CVSS score of 9.1, stems in Spring WebFlux applications that meet all the following conditions:

Affected versions include Spring Security 5.7.x through 6.3.x. The updates are available across both Open-Source Software (OSS) and Enterprise Support channels for specific versions.

Advertisements

To resolve this issue, Spring recommends updating to the latest secured versions:

Organizations urged to prioritize this update to protect against potential exploitation. Keeping software components current, particularly those that manage authorization, is critical to preventing unauthorized access.

Exit mobile version