CVE-2024-22257: Pivotal Software Spring Security
High severity, CVSS 8.2. EPSS: 1% chance of exploitation in the next 30 days.
In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.
Affected products
- Pivotal Software Spring Security: from 5.7.0, up to and including 5.7.11; from 5.8.0, up to and including 5.8.10; from 6.0.0, up to and including 6.0.9; from 6.1.0, up to and including 6.1.7; from 6.2.0, up to and including 6.2.2
Published 2024-03-18. Last modified 2026-06-30.