Spring Boot
cpe:2.3:a:pivotal_software:spring_boot:*:*:*:*:*:*:*, +1 more
- >= 4.0.0, <= 4.0.3
- >= 3.5.0, <= 3.5.11
- >= 3.4.0, <= 3.4.14
A vulnerability allowing authentication bypass has been identified in Spring Boot applications that use Actuator. This issue arises when an application endpoint requiring authentication is placed under a specific path that is already assigned to a custom Health Group with an additional path configuration. The vulnerability affects Spring Boot versions 4.0.0 prior to 4.0.3, 3.5.0 prior to 3.5.11, and 3.4.0 prior to 3.4.15.
Exploitation of this vulnerability allows unauthorized access to endpoints that require authentication, potentially leading to unauthorized actions or information disclosure.
Users of affected Spring Boot versions should upgrade to 4.0.4, 3.5.12, or 3.4.15, depending on their current version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.