CVE-2024-38821
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/10/2024
Last modified:
24/01/2025
Description
Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances.<br />
<br />
For this to impact an application, all of the following must be true:<br />
<br />
* It must be a WebFlux application<br />
* It must be using Spring&#39;s static resources support<br />
* It must have a non-permitAll authorization rule applied to the static resources support
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL