Skip to content
Launch GitLab Knowledge Graph

Investigate vulnerability: Authorization bypass in Spring Security

Issue created from vulnerability 17

Description:

In Spring Security versions 5.5.6 and 5.5.7 and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.

  • Severity: critical
  • Location: pom.xml

Solution:

Upgrade to versions 5.4.11, 5.5.7, 5.6.4 or above.

Identifiers:

Links:

Scanner:

  • Name: GitLab SBoM Vulnerability Scanner