CVE-2024-38810

CVSS V2 None CVSS V3 None
Description
Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.
Overview
  • CVE ID
  • CVE-2024-38810
  • Assigner
  • vmware
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-08-20T03:35:24.795Z
  • Last Modified Date
  • 2024-08-20T03:35:24.795Z
References
Reference URL Reference Tags
https://spring.io/security/cve-2024-38810
History
Created Old Value New Value Data Type Notes
2024-08-20 13:15:43 Added to TrackCVE