CVE-2024-22257
EUVD-2024-090818.03.2024, 15:15
In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| pivotal_software | spring_security | 5.7.0 ≤ 𝑥 ≤ 5.7.11 | ADP |
| pivotal_software | spring_security | 5.8.0 ≤ 𝑥 ≤ 5.8.10 | ADP |
| pivotal_software | spring_security | 6.0.0 ≤ 𝑥 ≤ 6.0.9 | ADP |
| pivotal_software | spring_security | 6.1.0 ≤ 𝑥 ≤ 6.1.7 | ADP |
| pivotal_software | spring_security | 6.2.0 ≤ 𝑥 ≤ 6.2.2 | ADP |
Common Weakness Enumeration