Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2598 | Spring Security Missing Authorization vulnerability |
Github GHSA |
GHSA-hmqf-wpq9-jq83 | Spring Security Missing Authorization vulnerability |
Fri, 28 Feb 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware spring Security |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vmware
Vmware spring Security |
Tue, 20 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 20 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Aug 2024 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective. | |
| Title | Missing Authorization When Using @AuthorizeReturnObject | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-08-20T13:34:50.068Z
Reserved: 2024-06-19T22:31:57.187Z
Link: CVE-2024-38810
Updated: 2024-08-20T13:34:46.333Z
Status : Analyzed
Published: 2024-08-20T04:15:07.993
Modified: 2025-02-28T22:37:56.503
Link: CVE-2024-38810
OpenCVE Enrichment
No data.
EUVD
Github GHSA