Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi Security
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Mar 6, 2023
Description
Published by the National Vulnerability Database
Oct 29, 2010
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jul 8, 2022
Last updated
Mar 6, 2023
VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
References