漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Servlet Path Not Correctly Included in Path Matching of HttpSecurity#securityMatchers
Vulnerability Description
Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components will not be exercised as intended by the application. This can lead to the authentication, authorization, and other security controls being rendered inactive on intended requests.This issue affects Spring Security: from 7.0.0 through 7.0.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
N/A
Vulnerability Title
Spring Security 安全漏洞
Vulnerability Description
Spring Security是Spring开源的一款具有认证和授权功能的安全框架。 Spring Security 7.0.0版本至7.0.4版本存在安全漏洞,该漏洞源于使用securityMatchers(String)和PathPatternRequestMatcher.Builder bean来前置servlet路径时,匹配请求可能失败,导致身份验证、授权和其他安全控制失效。
CVSS Information
N/A
Vulnerability Type
N/A