Search

Find a vulnerability

Search criteria

    2 vulnerabilities by pivotal_software

    CVE-2024-22257 (GCVE-0-2024-22257)

    Vulnerability from cvelistv5 – Published: 2024-03-18 14:18 – Updated: 2026-06-30 13:13
    VLAI
    Summary
    In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-12 15:22 UTC
    CWE
    • Possible Broken Access Control in Spring Security With Direct Use of AuthenticatedVoter
    • CWE-862 - Missing Authorization
    Impacted products
    Vendor Product Version
    N/A Spring Security Affected: 6.2.0 to 6.2.2, 6.1.0 to 6.1.7, 6.0.0 to 6.0.9, 5.8.0 to 5.8.10, 5.7.0 to 5.7.11
    Create a notification for this product.
    pivotal_software spring_security Affected: 5.7.0 , ≤ 5.7.11 (custom)
    Affected: 5.8.0 , ≤ 5.8.10 (custom)
    Affected: 6.0.0 , ≤ 6.0.9 (custom)
    Affected: 6.1.0 , ≤ 6.1.7 (custom)
    Affected: 6.2.0 , ≤ 6.2.2 (custom)
        cpe:2.3:a:pivotal_software:spring_security:5.7.0:*:*:*:*:*:*:*
        cpe:2.3:a:pivotal_software:spring_security:5.8.0:*:*:*:*:*:*:*
        cpe:2.3:a:pivotal_software:spring_security:6.0.0:*:*:*:*:*:*:*
        cpe:2.3:a:pivotal_software:spring_security:6.1.0:*:*:*:*:*:*:*
        cpe:2.3:a:pivotal_software:spring_security:6.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:pivotal_software:spring_security:5.7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:pivotal_software:spring_security:5.8.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:pivotal_software:spring_security:6.0.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:pivotal_software:spring_security:6.1.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:pivotal_software:spring_security:6.2.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "spring_security",
                "vendor": "pivotal_software",
                "versions": [
                  {
                    "lessThanOrEqual": "5.7.11",
                    "status": "affected",
                    "version": "5.7.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "5.8.10",
                    "status": "affected",
                    "version": "5.8.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "6.0.9",
                    "status": "affected",
                    "version": "6.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "6.1.7",
                    "status": "affected",
                    "version": "6.1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "6.2.2",
                    "status": "affected",
                    "version": "6.2.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-22257",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-12T15:22:14.458591Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-862",
                    "description": "CWE-862 Missing Authorization",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-12T15:32:11.373Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2026-06-30T13:13:48.866Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://github.com/dependency-check/DependencyCheck/issues/8642"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://spring.io/security/cve-2024-22257"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240419-0005/"
              }
            ],
            "title": "CVE Program Container",
            "x_generator": {
              "engine": "ADPogram 0.0.1"
            }
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Spring Security",
              "vendor": "N/A",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.2.0 to 6.2.2, 6.1.0 to 6.1.7, 6.0.0 to 6.0.9, 5.8.0 to 5.8.10, 5.7.0 to 5.7.11"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to \n5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, \nversions 6.2.x prior to 6.2.3, an application is possible vulnerable to \nbroken access control when it directly uses the \u003ccode\u003eAuthenticatedVoter#vote\u003c/code\u003e passing a \u003ccode\u003enull\u003c/code\u003e Authentication parameter."
                }
              ],
              "value": "In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to \n5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, \nversions 6.2.x prior to 6.2.3, an application is possible vulnerable to \nbroken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Possible Broken Access Control in Spring Security With Direct Use of AuthenticatedVoter",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-04-19T07:05:54.309Z",
            "orgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d",
            "shortName": "vmware"
          },
          "references": [
            {
              "url": "https://spring.io/security/cve-2024-22257"
            },
            {
              "url": "https://security.netapp.com/advisory/ntap-20240419-0005/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d",
        "assignerShortName": "vmware",
        "cveId": "CVE-2024-22257",
        "datePublished": "2024-03-18T14:18:52.986Z",
        "dateReserved": "2024-01-08T18:43:15.942Z",
        "dateUpdated": "2026-06-30T13:13:48.866Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-22243 (GCVE-0-2024-22243)

    Vulnerability from cvelistv5 – Published: 2024-02-23 05:03 – Updated: 2025-02-13 17:33
    VLAI
    Title
    CVE-2024-22243: Spring Framework URL Parsing with Host Validation
    Summary
    Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-27 00:00 UTC
    CWE
    • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
    Impacted products
    Vendor Product Version
    Spring Spring Framework Affected: 6.0.x , < 6.0.17 (6.0.17)
    Affected: 6.1.x , < 6.1.4 (6.1.4)
    Affected: 5.3.x , < 5.3.32 (5.3.32)
    Create a notification for this product.
    vmware spring_framework Affected: 6.0.0 , < 6.0.17 (custom)
        cpe:2.3:a:vmware:spring_framework:6.0.0:-:*:*:*:*:*:*
    Create a notification for this product.
    vmware spring_framework Affected: 6.1.0 , < 6.1.4 (custom)
        cpe:2.3:a:vmware:spring_framework:6.1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    pivotal_software spring_framework Affected: 5.3.0 , < 5.3.32 (custom)
        cpe:2.3:a:pivotal_software:spring_framework:5.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    netapp active_iq_unified_manager Affected: 5.0
        cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
    Create a notification for this product.
    netapp active_iq_unified_manager Affected: 5.0
        cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
    Create a notification for this product.
    netapp active_iq_unified_manager Affected: 5.0
        cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
    Create a notification for this product.
    Date Public
    2024-02-21 16:18
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:vmware:spring_framework:6.0.0:-:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "spring_framework",
                "vendor": "vmware",
                "versions": [
                  {
                    "lessThan": "6.0.17",
                    "status": "affected",
                    "version": "6.0.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:vmware:spring_framework:6.1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "spring_framework",
                "vendor": "vmware",
                "versions": [
                  {
                    "lessThan": "6.1.4",
                    "status": "affected",
                    "version": "6.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:pivotal_software:spring_framework:5.3.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "spring_framework",
                "vendor": "pivotal_software",
                "versions": [
                  {
                    "lessThan": "5.3.32",
                    "status": "affected",
                    "version": "5.3.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "active_iq_unified_manager",
                "vendor": "netapp",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "active_iq_unified_manager",
                "vendor": "netapp",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "active_iq_unified_manager",
                "vendor": "netapp",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-22243",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-27T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-601",
                    "description": "CWE-601 URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-27T03:55:12.310Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-09-10T05:02:44.560Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://spring.io/security/cve-2024-22243"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240524-0001/"
              },
              {
                "url": "http://seclists.org/fulldisclosure/2024/Sep/24"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "Spring Framework",
              "vendor": "Spring",
              "versions": [
                {
                  "lessThan": "6.0.17",
                  "status": "affected",
                  "version": "6.0.x",
                  "versionType": "6.0.17"
                },
                {
                  "lessThan": "6.1.4",
                  "status": "affected",
                  "version": "6.1.x",
                  "versionType": "6.1.4"
                },
                {
                  "lessThan": "5.3.32",
                  "status": "affected",
                  "version": "5.3.x",
                  "versionType": "5.3.32"
                }
              ]
            }
          ],
          "datePublic": "2024-02-21T16:18:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eApplications that use \u003c/span\u003e\u003ccode\u003eUriComponentsBuilder\u003c/code\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;to parse an externally provided URL (e.g. through a query parameter) \u003c/span\u003e\u003cem\u003eAND\u003c/em\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;perform validation checks on the host of the parsed URL may be vulnerable to a \u003c/span\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://cwe.mitre.org/data/definitions/601.html\"\u003eopen redirect\u003c/a\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;attack or to a SSRF attack if the URL is used after passing validation checks.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "Applications that use UriComponentsBuilder\u00a0to parse an externally provided URL (e.g. through a query parameter) AND\u00a0perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html \u00a0attack or to a SSRF attack if the URL is used after passing validation checks."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-10T17:09:48.637Z",
            "orgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d",
            "shortName": "vmware"
          },
          "references": [
            {
              "url": "https://spring.io/security/cve-2024-22243"
            },
            {
              "url": "https://security.netapp.com/advisory/ntap-20240524-0001/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE-2024-22243: Spring Framework URL Parsing with Host Validation",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d",
        "assignerShortName": "vmware",
        "cveId": "CVE-2024-22243",
        "datePublished": "2024-02-23T05:03:54.426Z",
        "dateReserved": "2024-01-08T18:43:03.535Z",
        "dateUpdated": "2025-02-13T17:33:38.355Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }