#VU80880 Security features bypass in Spring Security - CVE-2023-34034
Published: September 19, 2023
Spring Security
VMware, Inc
Description
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to the usage of "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux. A remote unauthenticated attacker can trigger the vulnerability to bypass security restrictions.