CVE-2023-34034
ADVISORY - githubSummary
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
EPSS Score: 0.47909 (0.976)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Improper Preservation of Permissions
ADVISORY - gitlab
ADVISORY - redhat
Improper Neutralization of Section Delimiters
NIST
CREATED
UPDATED
ADVISORY IDCVE-2023-34034
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
9.1criticalGitHub
CVSS SCORE
9.1criticalRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2023-34034
EXPLOITABILITY SCORE
2.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)