Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching mechanisms, for example with regards to space trimming in path segments, can lead Spring Security to not recognize certain paths as not protected that are in fact mapped to Spring MVC controllers that should be protected. The problem is compounded by the fact that the Spring Framework provides richer features with regards to pattern matching as well as by the fact that pattern matching in each Spring Security and the Spring Framework can easily be customized creating additional differences.
{
"unresolved_ranges": [
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:pivotal_software:spring_framework:3.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:spring_framework:4.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:spring_framework:4.1.0:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:spring_framework:4.2.0:*:*:*:*:*:*:*"
],
"vendor_product": "pivotal_software:spring_framework",
"extracted_events": [
{
"introduced": "3.2.0"
},
{
"last_affected": "3.2.0"
},
{
"introduced": "4.0.0"
},
{
"last_affected": "4.0.0"
},
{
"introduced": "4.1.0"
},
{
"last_affected": "4.1.0"
},
{
"introduced": "4.2.0"
},
{
"last_affected": "4.2.0"
}
]
}
]
}{
"cpe": [
"cpe:2.3:a:vmware:spring_framework:3.2.1:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.2:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.3:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.4:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.5:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.6:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.7:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.8:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.9:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.10:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.11:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.12:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.13:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.14:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.15:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.16:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.17:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:3.2.18:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.0.5:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.0.6:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.0.7:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.0.8:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.0.9:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.1.1:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.1.2:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.1.3:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.1.4:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.1.5:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.1.6:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.1.7:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.1.8:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.1.9:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.2.1:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.2.2:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.2.3:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.2.4:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.2.5:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.2.6:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.2.7:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.2.8:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_framework:4.2.9:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "3.2.1"
},
{
"last_affected": "3.2.1"
},
{
"introduced": "3.2.2"
},
{
"last_affected": "3.2.2"
},
{
"introduced": "3.2.3"
},
{
"last_affected": "3.2.3"
},
{
"introduced": "3.2.4"
},
{
"last_affected": "3.2.4"
},
{
"introduced": "3.2.5"
},
{
"last_affected": "3.2.5"
},
{
"introduced": "3.2.6"
},
{
"last_affected": "3.2.6"
},
{
"introduced": "3.2.7"
},
{
"last_affected": "3.2.7"
},
{
"introduced": "3.2.8"
},
{
"last_affected": "3.2.8"
},
{
"introduced": "3.2.9"
},
{
"last_affected": "3.2.9"
},
{
"introduced": "3.2.10"
},
{
"last_affected": "3.2.10"
},
{
"introduced": "3.2.11"
},
{
"last_affected": "3.2.11"
},
{
"introduced": "3.2.12"
},
{
"last_affected": "3.2.12"
},
{
"introduced": "3.2.13"
},
{
"last_affected": "3.2.13"
},
{
"introduced": "3.2.14"
},
{
"last_affected": "3.2.14"
},
{
"introduced": "3.2.15"
},
{
"last_affected": "3.2.15"
},
{
"introduced": "3.2.16"
},
{
"last_affected": "3.2.16"
},
{
"introduced": "3.2.17"
},
{
"last_affected": "3.2.17"
},
{
"introduced": "3.2.18"
},
{
"last_affected": "3.2.18"
},
{
"introduced": "4.0.1"
},
{
"last_affected": "4.0.1"
},
{
"introduced": "4.0.2"
},
{
"last_affected": "4.0.2"
},
{
"introduced": "4.0.3"
},
{
"last_affected": "4.0.3"
},
{
"introduced": "4.0.4"
},
{
"last_affected": "4.0.4"
},
{
"introduced": "4.0.5"
},
{
"last_affected": "4.0.5"
},
{
"introduced": "4.0.6"
},
{
"last_affected": "4.0.6"
},
{
"introduced": "4.0.7"
},
{
"last_affected": "4.0.7"
},
{
"introduced": "4.0.8"
},
{
"last_affected": "4.0.8"
},
{
"introduced": "4.0.9"
},
{
"last_affected": "4.0.9"
},
{
"introduced": "4.1.1"
},
{
"last_affected": "4.1.1"
},
{
"introduced": "4.1.2"
},
{
"last_affected": "4.1.2"
},
{
"introduced": "4.1.3"
},
{
"last_affected": "4.1.3"
},
{
"introduced": "4.1.4"
},
{
"last_affected": "4.1.4"
},
{
"introduced": "4.1.5"
},
{
"last_affected": "4.1.5"
},
{
"introduced": "4.1.6"
},
{
"last_affected": "4.1.6"
},
{
"introduced": "4.1.7"
},
{
"last_affected": "4.1.7"
},
{
"introduced": "4.1.8"
},
{
"last_affected": "4.1.8"
},
{
"introduced": "4.1.9"
},
{
"last_affected": "4.1.9"
},
{
"introduced": "4.2.1"
},
{
"last_affected": "4.2.1"
},
{
"introduced": "4.2.2"
},
{
"last_affected": "4.2.2"
},
{
"introduced": "4.2.3"
},
{
"last_affected": "4.2.3"
},
{
"introduced": "4.2.4"
},
{
"last_affected": "4.2.4"
},
{
"introduced": "4.2.5"
},
{
"last_affected": "4.2.5"
},
{
"introduced": "4.2.6"
},
{
"last_affected": "4.2.6"
},
{
"introduced": "4.2.7"
},
{
"last_affected": "4.2.7"
},
{
"introduced": "4.2.8"
},
{
"last_affected": "4.2.8"
},
{
"introduced": "4.2.9"
},
{
"last_affected": "4.2.9"
}
],
"source": "CPE_STRING"
}{
"cpe": [
"cpe:2.3:a:vmware:spring_security:3.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:3.2.1:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:3.2.2:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:3.2.3:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:3.2.4:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:3.2.5:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:3.2.6:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:3.2.7:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:3.2.8:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:3.2.9:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:3.2.10:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:4.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:4.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:4.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:4.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:4.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:spring_security:4.1.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "3.2.0"
},
{
"last_affected": "3.2.0"
},
{
"introduced": "3.2.1"
},
{
"last_affected": "3.2.1"
},
{
"introduced": "3.2.2"
},
{
"last_affected": "3.2.2"
},
{
"introduced": "3.2.3"
},
{
"last_affected": "3.2.3"
},
{
"introduced": "3.2.4"
},
{
"last_affected": "3.2.4"
},
{
"introduced": "3.2.5"
},
{
"last_affected": "3.2.5"
},
{
"introduced": "3.2.6"
},
{
"last_affected": "3.2.6"
},
{
"introduced": "3.2.7"
},
{
"last_affected": "3.2.7"
},
{
"introduced": "3.2.8"
},
{
"last_affected": "3.2.8"
},
{
"introduced": "3.2.9"
},
{
"last_affected": "3.2.9"
},
{
"introduced": "3.2.10"
},
{
"last_affected": "3.2.10"
},
{
"introduced": "4.0.0"
},
{
"last_affected": "4.0.0"
},
{
"introduced": "4.0.1"
},
{
"last_affected": "4.0.1"
},
{
"introduced": "4.0.2"
},
{
"last_affected": "4.0.2"
},
{
"introduced": "4.0.3"
},
{
"last_affected": "4.0.3"
},
{
"introduced": "4.0.4"
},
{
"last_affected": "4.0.4"
},
{
"introduced": "4.1.0"
},
{
"last_affected": "4.1.0"
}
]
}