CVE-2021-22047

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/10/2021
Last modified:
01/11/2021

Description

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:* 3.4.0 (including) 3.4.13 (including)
cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:* 3.5.0 (including) 3.5.5 (including)


References to Advisories, Solutions, and Tools