CVE-2025-22223
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/03/2025
Last modified:
27/03/2025
Description
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. <br />
<br />
You are not affected if you are not using @EnableMethodSecurity, or<br />
you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM



