GHSA-g5h3-w546-pj7f

Suggest an improvement
Source
https://github.com/advisories/GHSA-g5h3-w546-pj7f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-g5h3-w546-pj7f/GHSA-g5h3-w546-pj7f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g5h3-w546-pj7f
Aliases
Published
2023-04-20T21:33:27Z
Modified
2024-12-06T05:24:46.188054Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Spring Boot Security Bypass with Wildcard Pattern Matching on Cloud Foundry
Details

In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to 2.7.11+. Users of older, unsupported versions should upgrade to 3.0.6+ or 2.7.11+.

Database specific
{
    "nvd_published_at": "2023-04-20T21:15:08Z",
    "cwe_ids": [],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2023-04-24T20:14:42Z"
}
References

Affected packages

Maven / org.springframework.boot:spring-boot-actuator-autoconfigure

Package

Name
org.springframework.boot:spring-boot-actuator-autoconfigure
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.0.6

Affected versions

3.*

3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5

Maven / org.springframework.boot:spring-boot-actuator-autoconfigure

Package

Name
org.springframework.boot:spring-boot-actuator-autoconfigure
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.7.0
Fixed
2.7.11

Affected versions

2.*

2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.7.10

Maven / org.springframework.boot:spring-boot-actuator-autoconfigure

Package

Name
org.springframework.boot:spring-boot-actuator-autoconfigure
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.0
Fixed
2.6.15

Affected versions

2.*

2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14

Maven / org.springframework.boot:spring-boot-actuator-autoconfigure

Package

Name
org.springframework.boot:spring-boot-actuator-autoconfigure
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.15

Affected versions

2.*

2.0.0.RELEASE
2.0.1.RELEASE
2.0.2.RELEASE
2.0.3.RELEASE
2.0.4.RELEASE
2.0.5.RELEASE
2.0.6.RELEASE
2.0.7.RELEASE
2.0.8.RELEASE
2.0.9.RELEASE
2.1.0.RELEASE
2.1.1.RELEASE
2.1.2.RELEASE
2.1.3.RELEASE
2.1.4.RELEASE
2.1.5.RELEASE
2.1.6.RELEASE
2.1.7.RELEASE
2.1.8.RELEASE
2.1.9.RELEASE
2.1.10.RELEASE
2.1.11.RELEASE
2.1.12.RELEASE
2.1.13.RELEASE
2.1.14.RELEASE
2.1.15.RELEASE
2.1.16.RELEASE
2.1.17.RELEASE
2.1.18.RELEASE
2.2.0.RELEASE
2.2.1.RELEASE
2.2.2.RELEASE
2.2.3.RELEASE
2.2.4.RELEASE
2.2.5.RELEASE
2.2.6.RELEASE
2.2.7.RELEASE
2.2.8.RELEASE
2.2.9.RELEASE
2.2.10.RELEASE
2.2.11.RELEASE
2.2.12.RELEASE
2.2.13.RELEASE
2.3.0.RELEASE
2.3.1.RELEASE
2.3.2.RELEASE
2.3.3.RELEASE
2.3.4.RELEASE
2.3.5.RELEASE
2.3.6.RELEASE
2.3.7.RELEASE
2.3.8.RELEASE
2.3.9.RELEASE
2.3.10.RELEASE
2.3.11.RELEASE
2.3.12.RELEASE
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.4.10
2.4.11
2.4.12
2.4.13
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14