CVE-2025-22223

MEDIUM5.3EPSS 0.03%

Spring Security Vulnerable to Authorization Bypass via Security Annotations

Published: 3/24/2025Modified: 2/4/2026
Also known as:GHSA-hh3m-g4qj-4835CGA-wv8q-rf4r-4vq7

Description

Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass.  You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References (4)