Security features bypass in Spring Security - CVE-2025-22228

 

Security features bypass in Spring Security - CVE-2025-22228

Published: March 19, 2025


Vulnerability identifier: #VU105881
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22228
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to the application.

The vulnerability exists due to BCryptPasswordEncoder does not properly enforce maximum password length and will return "true" for passwords larger than 72 characters as long as the first 72 characters are the same. This can be used set weak passwords that can be easily brute-forced.


Affected software

Spring Security
Netcool Operations Insight
Crucible Server
Crucible Data Center
Jira Service Management Data Center
Jira Service Management Server
IBM Sterling Control Center
Confluence Data Center
Bitbucket Data Center
IBM Common Licensing
Bamboo Server
Jira Software Data Center
IBM Cloud Pak for Business Automation
IBM Cloud Object Storage Systems
watsonx.data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
DevOps Solution Workbench
IBM Business Automation Manager Open Editions
OpenShift Developer Tools and Services
Red Hat Camel for Spring Boot
Confluence Server
Bitbucket Server
Jira Software Server
Oracle Banking Liquidity Management
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
Operational Decision Manager

How to mitigate CVE-2025-22228

Install updates from vendor's website.

Spring Security - addressed in versions 5.7.16, 5.8.18, 6.0.16, 6.1.14, 6.2.10, 6.3.8, 6.4.4
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
Crucible Server - update to 4.9.11
Crucible Data Center - update to 4.9.11
Jira Service Management Data Center - addressed in versions 5.12.24, 10.3.7, 10.7.1
Jira Service Management Server - addressed in versions 5.12.24, 10.3.7, 10.7.1
IBM Sterling Control Center - addressed in versions 6.3.1.0.4, 6.4.0.0.2
Confluence Data Center - addressed in versions 8.5.23, 9.2.5, 9.5.1
Confluence Server - addressed in versions 8.5.23, 9.2.5, 9.5.1
Bitbucket Server - update to 8.19.25
Bitbucket Data Center - update to 8.19.25
IBM Business Automation Manager Open Editions - update to 9.2.1
IBM Common Licensing - update to 9.0.0.2
Bamboo Server - addressed in versions 9.6.14, 10.2.3
Jira Software Server - addressed in versions 9.12.24, 10.3.7, 10.7.1
Jira Software Data Center - addressed in versions 9.12.24, 10.3.7, 10.7.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
jenkins (Red Hat package) - addressed in versions 2.504.2.1750846524-3.el9, 2.504.2.1750851690-3.el9, 2.504.2.1750856366-3.el8, 2.504.2.1750857144-3.el9, 2.504.2.1750903189-3.el8, 2.504.2.1750916374-3.el8, 2.504.2.1750932984-3.el8
IBM Cloud Object Storage Systems - addressed in versions 3.19.0.54, 3.19.2.72
Red Hat Camel for Spring Boot - update to 4.8.5
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1750933270-1.el8, 4.13.1750916671-1.el8, 4.14.1750903529-1.el8, 4.15.1750856638-1.el8, 4.16.1750857315-1.el9, 4.17.1750851950-1.el9, 4.18.1750846854-1.el9
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 49, 8.11.1 Interim fix 47, 8.12.0.1 Interim fix 31, 9.0.0.1 Interim fix 15, 9.5.0.0 Interim fix 7

External References

Related Security Bulletins