CVE-2023-20860
published 2023-03-27CVE-2023-20860: Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
3.51%
87.9th percentile
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | >= 5.3.0 < 5.3.26 | 5.3.26 |
| vmware | spring_framework | >= 6.0.0 < 6.0.7 | 6.0.7 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect use of '**' as a pattern in Spring Security mvcRequestMatcher configuration, which creates a pattern matching mismatch between Spring Security and Spring MVC enabling security bypass ↗
- →Flag Spring Framework versions 6.0.0–6.0.6 and 5.3.0–5.3.25 in inventory scans as vulnerable to this security bypass ↗
- →HTTP-based remote exploitation is confirmed; monitor for unexpected access to Spring MVC endpoints that should be restricted by Spring Security rules using '**' wildcard patterns ↗
- ·The vulnerability is specifically triggered by use of '**' (un-prefixed double wildcard) as a pattern in Spring Security mvcRequestMatcher configuration; other wildcard patterns are not implicated ↗
- ·Debian tracks this CVE as open across bookworm, bullseye, forky, sid, and trixie — no fix available in those branches at time of reporting ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
osv·2023-03-28
CVE-2023-20860 [CRITICAL] Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
GHSA
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
ghsa·2023-03-28
CVE-2023-20860 [CRITICAL] Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
OSV
CVE-2023-20860: Spring Framework running version 6
osv·2023-03-27·CVSS 7.5
CVE-2023-20860 [HIGH] CVE-2023-20860: Spring Framework running version 6
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Spring Framework) — CVE-2023-20860
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2023-20860 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Spring Framework) — CVE-2023-20860
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Spring Framework) vulnerability
CVE: CVE-2023-20860
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Red Hat
springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern
vendor_redhat·2023-03-20·CVSS 7.5
CVE-2023-20860 [HIGH] CWE-155 springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern
springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
A flaw was found in Spring Framework. In this vulnerability, a security bypass is possible due to the behavior of the wildcard pattern.
Package: springframework (A-MQ Clients 2) - Not affected
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: org.keycloak-keycloak-parent (Migration Toolkit for Applications 6) - Not affected
Package: org.keycloak-keycloak-parent (Migration Toolkit for
Debian
CVE-2023-20860: libspring-java - Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a...
vendor_debian·2023·CVSS 7.5
CVE-2023-20860 [HIGH] CVE-2023-20860: libspring-java - Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a...
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-27
Published