发布于3月6日3月6日 Members Red Hat OpenShift: CVE-2023-20860: springframework: Security Bypass With Un-Prefixed Double Wildcard Pattern Severity 8 CVSS (AV:N/AC:L/Au:N/C:N/I:C/A:N) Published 03/27/2023 Created 06/27/2023 Added 06/26/2023 Modified 01/30/2025 Description Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass. Solution(s) linuxrpm-upgrade-jenkins References https://attackerkb.com/topics/cve-2023-20860 CVE - 2023-20860 RHSA-2023:2100 RHSA-2023:3185 RHSA-2023:3610 RHSA-2023:3622 RHSA-2023:3625 RHSA-2023:3663 RHSA-2023:3771 RHSA-2023:3954 RHSA-2023:4612 RHSA-2023:4983 View more