Severity
9.8CRITICAL
EPSS
8.4%
top 7.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 31
Latest updateJan 15

Description

Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and include dispatcher types. The application uses the AuthorizationFilter either manually or via the authorizeHttpRequests() method. The application configures the FilterChainProxy to app

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDvmware/spring_security5.6.05.6.9+1
CVEListV5spring_by_vmware5.7 to 5.7.4, 5.6 to 5.6.8 and older versions

🔴Vulnerability Details

4
OSV
Spring Security authorization rules can be bypassed via forward or include dispatcher types2022-11-01
GHSA
Spring Security authorization rules can be bypassed via forward or include dispatcher types2022-11-01
OSV
CVE-2022-31692: Spring Security, versions 52022-10-31
CVEList
CVE-2022-31692: Spring Security, versions 52022-10-31

📋Vendor Advisories

5
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Common Core (Spring Security) — CVE-2022-316922024-01-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Vision (Spring Security) — CVE-2022-316922023-07-15
Oracle
Oracle Oracle Communications Risk Matrix: Authentication (Spring Security) — CVE-2022-316922023-04-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: REST API (Spring Security) — CVE-2022-316922023-01-15
Red Hat
spring-security: Authorization rules can be bypassed via forward or include dispatcher types in Spring Security2022-10-31
CVE-2022-31692 (CRITICAL CVSS 9.8) | Spring Security | cvebase.io