#VU99267 Improper Authorization in Spring Security - CVE-2024-38821
Published: October 23, 2024 / Updated: October 30, 2024
Spring Security
VMware, Inc
Description
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to improper implementation of authorization checks when accessing static resources in WebFlux application. A remote non-authenticated attacker can bypass authorization process and gain unauthorized access to the application.