In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with .
in the regular expression are possibly vulnerable to an authorization bypass.
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-beans-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-context-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-context-support-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-core-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-expression-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-instrument-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-jdbc-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-jms-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-orm-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-oxm-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-test-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-transaction-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-web-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-web-struts-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" } ] }
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-beans-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-context-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-context-support-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-core-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-expression-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-instrument-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-jdbc-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-jms-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-orm-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-oxm-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-test-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-transaction-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-web-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-beans-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-context-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-context-support-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-core-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-expression-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-instrument-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-jdbc-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-jms-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-messaging-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-orm-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-oxm-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-test-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-transaction-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-web-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "4.3.22-1~18.04.1~esm1" } ] }
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-beans-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-context-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-context-support-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-core-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-expression-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-instrument-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-jdbc-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-jms-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-messaging-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-orm-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-oxm-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-test-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-transaction-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-web-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-beans-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-context-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-context-support-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-core-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-expression-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-instrument-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-jdbc-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-jms-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-messaging-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-orm-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-oxm-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-test-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-transaction-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-web-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "4.3.30-1" } ] }
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-beans-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-context-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-context-support-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-core-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-expression-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-instrument-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-jdbc-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-jms-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-messaging-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-orm-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-oxm-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-test-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-transaction-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-web-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "4.3.30-2" } ] }
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-beans-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-context-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-context-support-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-core-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-expression-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-instrument-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-jdbc-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-jms-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-messaging-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-orm-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-oxm-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-test-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-transaction-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-web-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "4.3.30-2ubuntu1" } ] }