CVE-2025-22223
MEDIUMSpring Security 6.4.0-6.4.3 - Auth Bypass
Title source: llmDescription
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods
Exploits (1)
References (1)
Scores
CVSS v3
5.3
EPSS
0.0004
EPSS Percentile
11.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-290
Status
published
Products (2)
org.springframework.security/spring-security-core
6.4.0 - 6.4.4Maven
Spring/Spring Security
6.4.0-6.4.3
Published
Mar 24, 2025
Tracked Since
Feb 18, 2026