/plushcap/analysis/snyk/snyk-spring-security-authorization-bypass-cve-2022-31692

Exploring the Spring Security authorization bypass (CVE-2022-31692)

What's this blog post about?

A new authorization bypass vulnerability (CVE-2022-31692) has been discovered in Spring Security 5, affecting a specific set of use cases. The issue allows non-admin users to access admin pages without proper authorization. To mitigate this security problem, it is advised to upgrade to the newer version of Spring Security (version 5.6.9 or beyond). If updating is not possible, changing the filter definition can also help. Keeping dependencies up to date is crucial for maintaining application security.

Company
Snyk

Date published
Dec. 16, 2022

Author(s)
Brian Vermeer

Word count
1121

Language
English

Hacker News points
None found.


By Matt Makai. 2021-2024.