CVE-2023-34042

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/02/2024
Last modified:
29/11/2024

Description

The spring-security.xsd file inside the <br /> spring-security-config jar is world writable which means that if it were<br /> extracted it could be written by anyone with access to the file system.<br /> <br /> <br /> While there are no known exploits, this is an example of “CWE-732: <br /> Incorrect Permission Assignment for Critical Resource” and could result <br /> in an exploit. Users should update to the latest version of Spring <br /> Security to mitigate any future exploits found around this issue.<br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* 5.8.4 (including) 5.8.7 (excluding)
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* 6.0.4 (including) 6.0.7 (excluding)
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* 6.1.1 (including) 6.1.4 (excluding)
cpe:2.3:a:vmware:spring_security:5.7.9:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:5.7.10:*:*:*:*:*:*:*