#VU63345 Improper Authorization in Spring Security - CVE-2022-22978
Published: May 17, 2022 / Updated: March 18, 2023
Spring Security
VMware, Inc
Description
The vulnerability allows a remote attacker to bypass authorization process.
The vulnerability exists due to input validation error when processing untrusted input in applications that are using RegexRequestMatcher with `.` in the regular expression. A remote non-authenticated attacker can bypass authorization checks.