CVE-2024-22257
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/03/2024
Last modified:
13/02/2025
Description
In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to <br />
5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, <br />
versions 6.2.x prior to 6.2.3, an application is possible vulnerable to <br />
broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.
Impact
Base Score 3.x
8.20
Severity 3.x
HIGH