Vulnerability Description
In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://security.netapp.com/advisory/ntap-20240419-0005/
- https://spring.io/security/cve-2024-22257
- https://security.netapp.com/advisory/ntap-20240419-0005/
- https://spring.io/security/cve-2024-22257
FAQ
What is CVE-2024-22257?
CVE-2024-22257 is a vulnerability with a CVSS score of 8.2 (HIGH). In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vul...
How severe is CVE-2024-22257?
CVE-2024-22257 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-22257?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.