Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using ** as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spring_framework | Vmware | 5.3.0 (including) | 5.3.26 (excluding) |
Spring_framework | Vmware | 6.0.0 (including) | 6.0.7 (excluding) |
AMQ Broker 7.10.3 | RedHat | springframework | * |
OCP-Tools-4.12-RHEL-8 | RedHat | jenkins-0:2.401.1.1686649641-3.el8 | * |
OCP-Tools-4.13-RHEL-8 | RedHat | jenkins-0:2.401.1.1686680404-3.el8 | * |
OpenShift Developer Tools and Services for OCP 4.11 | RedHat | jenkins-0:2.401.1.1686831596-3.el8 | * |
Red Hat Fuse 7.12 | RedHat | springframework | * |
Red Hat OpenShift Container Platform 4.10 | RedHat | jenkins-0:2.401.1.1685677065-1.el8 | * |
Red Hat support for Spring Boot 2.7.13 | RedHat | springframework | * |
Red Hat Virtualization Engine 4.4 | RedHat | ovirt-dependencies-0:4.5.3-1.el8ev | * |
RHINT Camel-Springboot 3.20.1 | RedHat | springframework | * |
RHPAM 7.13.4 async | RedHat | springframework | * |
Libspring-java | Ubuntu | bionic | * |
Libspring-java | Ubuntu | kinetic | * |
Libspring-java | Ubuntu | lunar | * |
Libspring-java | Ubuntu | mantic | * |
Libspring-java | Ubuntu | trusty | * |
Libspring-java | Ubuntu | trusty/esm | * |
Libspring-java | Ubuntu | xenial | * |