CVE-2024-38821

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/10/2024
Last modified:
24/01/2025

Description

Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances.<br /> <br /> For this to impact an application, all of the following must be true:<br /> <br /> * It must be a WebFlux application<br /> * It must be using Spring&amp;#39;s static resources support<br /> * It must have a non-permitAll authorization rule applied to the static resources support