PT-2025-22336 · Spring · Spring Security Aspects
Published
2025-05-19
·
Updated
2025-05-26
·
CVE-2025-41232
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Security Aspects (affected versions not specified)
Description
The issue concerns Spring Security Aspects not correctly locating method security annotations on private methods, potentially causing an authorization bypass. This can affect applications using @EnableMethodSecurity(mode=ASPECTJ) and spring-security-aspects with Spring Security method annotations on private methods. The target method may be invoked without proper authorization.
Recommendations
For applications using @EnableMethodSecurity(mode=ASPECTJ) and spring-security-aspects with Spring Security-annotated private methods, consider avoiding the use of such configurations until a fix is available.
As a temporary workaround, consider disabling the use of Spring Security annotations on private methods until a patch is available.
Restrict access to methods with Spring Security annotations to minimize the risk of exploitation.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Security Aspects