A AegiFlow
CRITICALCVSS 9.3EPSS 1.7%

CVE-2024-38821

Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications

Published
2024-10-28
Modified
2026-08-31
EPSS percentile
76%
Aliases
GHSA-c4q5-6c82-3qpw
Sources
github-advisory

Summary

Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all of the following must be true: * It must be a WebFlux application * It must be using Spring's static resources support * It must have a non-permitAll authorization rule applied to the static resources support

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.springframework.security:spring-security-web5.8.15, 6.2.7, 6.0.13, 6.1.11, 6.3.4, 5.7.13

Remediation: Upgrade to 5.8.15 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.