CVE-2025-22223
published 2025-03-24CVE-2025-22223: Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.48%
38.7th percentile
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass.
You are not affected if you are not using @EnableMethodSecurity, or
you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_security | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
spring-security: authorization bypass via incorrectly locating method security annotations on parameterized types or methods
vendor_redhat·2025-03-24·CVSS 5.3
CVE-2025-22223 [MEDIUM] CWE-290 spring-security: authorization bypass via incorrectly locating method security annotations on parameterized types or methods
spring-security: authorization bypass via incorrectly locating method security annotations on parameterized types or methods
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass.
You are not affected if you are not using @EnableMethodSecurity, or
you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods
A flaw was found in the Spring Security framework. In certain configurations, an authorization bypass vulnerability may be exploited due to Spring Security not correctly locating method security annotations on parameterized types or methods.
Statement: This issue does not affect you if you are not us
GHSA
Spring Security Vulnerable to Authorization Bypass via Security Annotations
ghsa·2025-03-24
CVE-2025-22223 [MEDIUM] CWE-290 Spring Security Vulnerable to Authorization Bypass via Security Annotations
Spring Security Vulnerable to Authorization Bypass via Security Annotations
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass.
You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods
OSV
Spring Security Vulnerable to Authorization Bypass via Security Annotations
osv·2025-03-24
CVE-2025-22223 [MEDIUM] Spring Security Vulnerable to Authorization Bypass via Security Annotations
Spring Security Vulnerable to Authorization Bypass via Security Annotations
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass.
You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods
No detection rules found.
No public exploits indexed.
2025-03-24
Published