Spring Security permission check: bypass via anonymous token and empty whitelist
Security Advisory
High
zhi2000
Affected:
- zhi-commons/zhi-auth-client-spring-boot-starter v6.0.0
Referenced CVEs:
CVE-2026-92466 · 8.8
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.