Missing Authorization Vulnerability in Spring Security 6.3.0 and 6.3.1
CVE-2024-38810
7.5HIGH
What is CVE-2024-38810?
A vulnerability in Spring Security versions 6.3.0 and 6.3.1 allows attackers to bypass security annotations due to missing authorization checks when using @AuthorizeReturnObject. This flaw can render security measures ineffective, making it crucial for developers to apply security updates and address this issue promptly.
Affected Version(s)
spring security 6.3.x < 6.3.2