CVE-2023-34034
published 2023-07-19CVE-2023-34034: Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the…
PriorityP258critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.46%
87.7th percentile
Using "**" as a pattern in Spring Security configuration
for WebFlux creates a mismatch in pattern matching between Spring
Security and Spring WebFlux, and the potential for a security bypass.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | spring_security | >= 5.6.0 < 5.6.12 | 5.6.12 |
| vmware | spring_security | >= 5.7.0 < 5.7.10 | 5.7.10 |
| vmware | spring_security | >= 5.8.0 < 5.8.5 | 5.8.5 |
| vmware | spring_security | >= 6.0.0 < 6.0.5 | 6.0.5 |
| vmware | spring_security | >= 6.1.0 < 6.1.2 | 6.1.2 |
| vmware | spring_security | Spring Security 5.6.0 – 5.6.11 | — |
| vmware | spring_security | Spring Security 5.7.0 – 5.7.9 | — |
| vmware | spring_security | Spring Security 5.8.0 – 5.8.4 | — |
| vmware | spring_security | Spring Security 6.0.0 – 6.0.4 | — |
| vmware | spring_security | Spring Security 6.1.0 – 6.1.1 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect Spring Security WebFlux configurations using '**' as a pattern without a leading slash, which creates a pattern-matching mismatch enabling security bypass ↗
- →Flag pathMatchers expressions that do NOT have a leading slash before the path pattern (e.g., pathMatchers("home/**")), as these are the vulnerable form exploitable for security bypass ↗
- →Investigate HTTP requests targeting path segments that should be restricted; a server using path-based pattern matching in WebFlux may allow an attacker to bypass security settings for some request paths, potentially leading to information disclosure or access of functionality outside the user's permissions ↗
- ·Only Spring Security WebFlux (reactive stack) configurations are vulnerable; non-WebFlux (servlet-based) Spring Security configurations are not affected by this pattern-matching mismatch ↗
- ·Red Hat build of Quarkus (io.quarkus/quarkus-spring-security) and Red Hat Single Sign-On 7 are confirmed NOT affected; Red Hat Process Automation 7 IS affected; Red Hat JBoss Fuse 6 is out of support scope ↗
- ·Mitigation requires ensuring all path patterns have a leading slash prepended; patterns without a leading slash (e.g., 'home/**') remain vulnerable ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_oracle9.8CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Spring Security) — CVE-2023-34034
vendor_oracle·2024-07-15·CVSS 9.8
CVE-2023-34034 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Spring Security) — CVE-2023-34034
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Spring Security) vulnerability
CVE: CVE-2023-34034
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: PSR Designer (Spring Security) — CVE-2023-34034
vendor_oracle·2024-01-15·CVSS 9.8
CVE-2023-34034 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: PSR Designer (Spring Security) — CVE-2023-34034
Oracle Oracle Communications Applications Risk Matrix: PSR Designer (Spring Security) vulnerability
CVE: CVE-2023-34034
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Spring Security) — CVE-2023-34034
vendor_oracle·2023-10-15·CVSS 9.8
CVE-2023-34034 [CRITICAL] Oracle Oracle Communications Risk Matrix: Install/Upgrade (Spring Security) — CVE-2023-34034
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Spring Security) vulnerability
CVE: CVE-2023-34034
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Red Hat
spring-security-webflux: path wildcard leads to security bypass
vendor_redhat·2023-07-19·CVSS 9.1
CVE-2023-34034 [CRITICAL] CWE-145 spring-security-webflux: path wildcard leads to security bypass
spring-security-webflux: path wildcard leads to security bypass
Using "**" as a pattern in Spring Security configuration
for WebFlux creates a mismatch in pattern matching between Spring
Security and Spring WebFlux, and the potential for a security bypass.
A flaw was found in Spring Security's WebFlux framework pattern matching, where it does not properly evaluate certain patterns. A server using path-based pattern matching in WebFlux could allow an attacker to bypass security settings for some request paths, potentially leading to information disclosure, access of functionality outside the user's permissions, or denial of service.
Mitigation: Users of path-based URL determination should ensure that all their patterns have a slash prepended.
example:
pathMatchers("home/**") // vulnerabl
GHSA
Access Control Bypass in Spring Security
ghsa·2023-07-19
CVE-2023-34034 [CRITICAL] CWE-281 Access Control Bypass in Spring Security
Access Control Bypass in Spring Security
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
OSV
Access Control Bypass in Spring Security
osv·2023-07-19
CVE-2023-34034 [CRITICAL] Access Control Bypass in Spring Security
Access Control Bypass in Spring Security
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, April 2026 Security Update Review
blogs_qualys·2026-04-22
CVE-2025-6965 Oracle Critical Patch Update, April 2026 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 481 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 139, constituting about 28% of the total patches released. Oracle Financial Services Applications and Oracle Fusion Middleware followed, with 75 and 59 security patches.
376 of the 481 security patches provided by the April Critical Patch Update (about 78%)
Qualys
Oracle Critical Patch Update, July 2024 Security Update Review
blogs_qualys·2024-07-17
Oracle Critical Patch Update, July 2024 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle released its third quarterly edition of Critical Patch Update, which contains patches for 386 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In the third quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 95, constituting about 24% of the total patches released. Oracle Financial Services Applications and Oracle Fusion Middleware foll
Qualys
Oracle Critical Patch Security Update: July 2024 Review | Qualys
blogs_qualys·2024-07-17
Oracle Critical Patch Security Update: July 2024 Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle released its third quarterly edition of Critical Patch Update, which contains patches for 386 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In the third quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 95, constituting about 24% of the total patches released. Oracle Financial Services Applications and Oracle Fusion Middlewa
Qualys
Oracle Patch Update, January 2024 Security Update Review
blogs_qualys·2024-01-17
Oracle Patch Update, January 2024 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Oracle has released its first quarterly edition of Critical Patch Update, which contains patches for 389 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in a wide range of product families, including Oracle code and third-party components included in Oracle products.
In the first quarterly Oracle Critical Patch Update, Oracle Financial Services Applications received the highest number of patches, 71, constituting 18% of the total patches released. Oracle Communications and Oracle Communications Applications follow
Qualys
Oracle Patch Update, January 2024 Security Update Review | Qualys
blogs_qualys·2024-01-17
Oracle Patch Update, January 2024 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Oracle has released its first quarterly edition of Critical Patch Update, which contains patches for 389 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in a wide range of product families, including Oracle code and third-party components included in Oracle products.
In the first quarterly Oracle Critical Patch Update, Oracle Financial Services Applications received the highest number of patches, 71, constituting 18% of the total patches released. Oracle Communications and Oracle Communications Applications
Qualys
Oracle Patch Tuesday, October 2023 Security Update Review | Qualys
blogs_qualys·2023-10-18
Oracle Patch Tuesday, October 2023 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released its fourth quarterly edition of Critical Patch Update, which contains a group of patches for 387 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During the Q4 2023 Oracle Critical Patch Update, Oracle Financial Services Applications received the highest number of 103 patches, constituting 26% of the total patches released. Oracle Communications and Oracle Fusion Middleware fo
Qualys
Oracle Patch Tuesday, October 2023 Security Update Review
blogs_qualys·2023-10-18
Oracle Patch Tuesday, October 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released its fourth quarterly edition of Critical Patch Update, which contains a group of patches for 387 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During the Q4 2023 Oracle Critical Patch Update, Oracle Financial Services Applications received the highest number of 103 patches, constituting 26% of the total patches released. Oracle Communications and Oracle Fusion Middleware followed,
2023-07-19
Published