GHSA-4926-qpxg-6r3w

Suggest an improvement
Source
https://github.com/advisories/GHSA-4926-qpxg-6r3w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4926-qpxg-6r3w/GHSA-4926-qpxg-6r3w.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-4926-qpxg-6r3w
Aliases
  • CVE-2021-22047
Published
2022-05-24T19:19:03Z
Modified
2023-11-01T04:54:23.827286Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Exposure of Resource to Wrong Sphere in Spring Data REST
Details

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.

Database specific
{
    "nvd_published_at": "2021-10-28T16:15:00Z",
    "github_reviewed_at": "2022-06-22T18:29:53Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-668"
    ]
}
References

Affected packages

Maven / org.springframework.data:spring-data-rest-core

Package

Name
org.springframework.data:spring-data-rest-core
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.data/spring-data-rest-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.4.0
Fixed
3.4.14

Affected versions

3.*

3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.4.10
3.4.11
3.4.12
3.4.13

Database specific

{
    "last_known_affected_version_range": "<= 3.4.13"
}

Maven / org.springframework.data:spring-data-rest-core

Package

Name
org.springframework.data:spring-data-rest-core
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.data/spring-data-rest-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.5.0
Fixed
3.5.6

Affected versions

3.*

3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5

Database specific

{
    "last_known_affected_version_range": "<= 3.5.5"
}