#VU105880 Improper authorization in Spring Security - CVE-2025-22223
Published: March 19, 2025 / Updated: March 25, 2025
Spring Security
VMware, Inc
Description
The vulnerability allows a remote attacker to bypass authorization process.
The vulnerability exists due to an error in @EnableMethodSecurity when locating method security annotations on parameterized types or methods. A remote non-authenticated attacker can bypass authorization process and gain access to sensitive information.