CVE-2023-34034: VMware Spring Security

Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.

Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.

Affected products

  • VMware Spring Security: from 5.6.0, before 5.6.12 (fixed in 5.6.12); from 5.7.0, before 5.7.10 (fixed in 5.7.10); from 5.8.0, before 5.8.5 (fixed in 5.8.5); from 6.0.0, before 6.0.5 (fixed in 6.0.5); from 6.1.0, before 6.1.2 (fixed in 6.1.2)

Published 2023-07-19. Last modified 2026-06-17.