#VU75561 Input validation error in Pivotal Spring Framework - CVE-2023-20860
Published: April 27, 2023
Pivotal Spring Framework
Pivotal
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an input validation error caused by using the wildcard ("**") as a pattern in Spring Security configuration with the mvcRequestMatcher, which creates a mismatch in pattern matching between Spring Security and Spring MVC. A remote attacker can bypass certain security restrictions.