cbcvebase.
CVE-2023-20860
published 2023-03-27

CVE-2023-20860: Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a…

PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
3.51%
87.9th percentile
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianlibspring-java
vmwarespring_framework
vmwarespring_framework>= 5.3.0 < 5.3.265.3.26
vmwarespring_framework>= 6.0.0 < 6.0.76.0.7

Detection & IOCsextracted from sources · hover to see the quote

  • Detect use of '**' as a pattern in Spring Security mvcRequestMatcher configuration, which creates a pattern matching mismatch between Spring Security and Spring MVC enabling security bypass
  • Flag Spring Framework versions 6.0.0–6.0.6 and 5.3.0–5.3.25 in inventory scans as vulnerable to this security bypass
  • HTTP-based remote exploitation is confirmed; monitor for unexpected access to Spring MVC endpoints that should be restricted by Spring Security rules using '**' wildcard patterns
  • ·The vulnerability is specifically triggered by use of '**' (un-prefixed double wildcard) as a pattern in Spring Security mvcRequestMatcher configuration; other wildcard patterns are not implicated
  • ·Debian tracks this CVE as open across bookworm, bullseye, forky, sid, and trixie — no fix available in those branches at time of reporting

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.