CVE-2024-38821: Spring

Critical severity, CVSS 9.1. EPSS: 1.7% chance of exploitation in the next 30 days.

Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all of the following must be true: * It must be a WebFlux application * It must be using Spring's static resources support * It must have a non-permitAll authorization rule applied to the static resources support

Affected products

  • Spring Spring: from 5.7, before 5.7.13 (fixed in 5.7.13); from 5.8, before 5.8.15 (fixed in 5.8.15); from 6.0, before 6.0.13 (fixed in 6.0.13); from 6.1, before 6.1.11 (fixed in 6.1.11); from 6.2, before 6.2.7 (fixed in 6.2.7); from 6.3, before 6.3.4 (fixed in 6.3.4)
  • Spring Webflux: from 5.7, before 5.7.13 (fixed in 5.7.13); from 5.8x, before 5.8.15 (fixed in 5.8.15); from 6.0x, before 6.0.13 (fixed in 6.0.13); from 6.1x, before 6.1.11 (fixed in 6.1.11); from 6.2x, before 6.2.7 (fixed in 6.2.7); from 6.3x, before 6.3.4 (fixed in 6.3.4)

Published 2024-10-28. Last modified 2026-06-17.