Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Vmware Spring Framework和VMware Spring Security 授权问题漏洞
Vulnerability Description
Vmware Spring Framework是美国Vmware公司的一套开源的Java、JavaEE应用程序框架。该框架可帮助开发人员构建高质量的应用。VMware Spring Security是美国VMware 公司的一套为基于Spring的应用程序提供说明性安全保护的安全框架。 Pivotal Spring Security和Spring Framework 5.0.6之前版本中存在授权问题漏洞。当两个产品同时使用时,攻击者可利用该漏洞获取被限制方法的访问权限。
CVSS Information
N/A
Vulnerability Type
N/A