CVE-2025-22223
MEDIUM 5.3EPSS 0.5%
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. You are not affected if you are not using @EnableMethodSecurity, oryou do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods
- CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - EPSS
- 0.49% chance of exploitation in the next 30 days, 40th percentile
- Published
- 2025-03-24
Proof-of-concept exploits (1)
- 1ucky7/cve-2025-22223-demo-1.0.00★ · 2025-04-03