CVE-2023-34034
CRITICALSpring Security - SSRF
Title source: llmDescription
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
Exploits (1)
Scores
CVSS v3
9.1
EPSS
0.4791
EPSS Percentile
97.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-281
Status
published
Products (2)
org.springframework.security/spring-security-config
5.6.0 - 5.6.12Maven
vmware/spring_security
5.6.0 - 5.6.12
Published
Jul 19, 2023
Tracked Since
Feb 18, 2026