PT-2021-14846 · Spring · Spring Data Rest

Brian Schrader

·

Published

2021-10-28

·

Updated

2022-05-24

·

CVE-2021-22047

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Spring Data REST versions 3.4.0 through 3.4.13 Spring Data REST versions 3.5.0 through 3.5.5 Spring Data REST older unsupported versions
Description The issue affects HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping. These resources are exposed under additional URIs, which can potentially be accessed without authorization, depending on the Spring Security configuration.
Recommendations For Spring Data REST versions 3.4.0 through 3.4.13, update to a version outside of this range to mitigate the risk. For Spring Data REST versions 3.5.0 through 3.5.5, update to a version outside of this range to mitigate the risk. For Spring Data REST older unsupported versions, consider upgrading to a supported version to address the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22047
GHSA-4926-QPXG-6R3W

Affected Products

Spring Data Rest