CVE-2023-20860: Critical severity vmware spring framework vulnerability
A flaw was found in Spring Framework. In this vulnerability, a security bypass is possible due to the behavior of the wildcard pattern.
Other sources
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2023-20860?
CVE-2023-20860 is a vulnerability in Spring Framework that allows for a security bypass.
How does CVE-2023-20860 occur?
CVE-2023-20860 occurs when using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher, which creates a mismatch in pattern matching between Spring Security and Spring MVC.
Which versions of Spring Framework are affected by CVE-2023-20860?
Spring Framework versions 6.0.0 - 6.0.6 and 5.3.0 - 5.3.25 are affected by CVE-2023-20860.
How can I fix CVE-2023-20860?
To fix CVE-2023-20860, update your Spring Framework to version 6.0.7 or 5.3.26, depending on the version you are currently using.
Where can I find more information about CVE-2023-20860?
You can find more information about CVE-2023-20860 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-20860), [Spring Security](https://spring.io/security/cve-2023-20860), [NetApp](https://security.netapp.com/advisory/ntap-20230505-0006/).