CVE-2022-31692
spring-security: Authorization rules can be bypassed via forward or include dispatcher types in Spring Security
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and include dispatcher types. The application uses the AuthorizationFilter either manually or via the authorizeHttpRequests() method. The application configures the FilterChainProxy to apply to forward and/or include requests (e.g. spring.security.filter.dispatcher-types = request, error, async, forward, include). The application may forward or include the request to a higher privilege-secured endpoint.The application configures Spring Security to apply to every dispatcher type via authorizeHttpRequests().shouldFilterAllDispatcherTypes(true)
Spring Security, las versiones 5.7 anteriores a 5.7.5 y 5.6 anteriores a 5.6.9 podrían ser susceptibles a que las reglas de autorización se omitan mediante reenvío o incluyan tipos de despachadores. Específicamente, una aplicación es vulnerable cuando se cumple todo lo siguiente: La aplicación espera que Spring Security aplique seguridad para reenviar e incluir tipos de despachadores. La aplicación utiliza AuthorizationFilter manualmente o mediante el método AuthorizeHttpRequests(). La aplicación configura FilterChainProxy para aplicarlo a solicitudes de reenvío y/o inclusión (e.g. spring.security.filter.dispatcher-types = request, error, async, forward, include). La aplicación puede reenviar o incluir la solicitud a endpoint con privilegios más altos. La aplicación configura Spring Security para aplicar a cada tipo de despachador a través de AuthorizeHttpRequests().shouldFilterAllDispatcherTypes(true)
A flaw was found in the spring-security framework. Spring Security could allow a remote attacker to bypass security restrictions caused by an issue when using forward or include dispatcher types. By sending a specially-crafted request, an attacker can bypass authorization rules.
Multicluster Engine for Kubernetes 2.2.4 images Multicluster engine for Kubernetes provides the foundational components that are necessary for the centralized management of multiple Kubernetes-based clusters across data centers, public clouds, and private clouds. You can use the engine to create new Red Hat OpenShift Container Platform clusters or to bring existing Kubernetes-based clusters under management by importing them. After the clusters are managed, you can use the APIs that are provided by the engine to distribute configuration based on placement policy.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-25 CVE Reserved
- 2022-10-31 CVE Published
- 2023-10-29 First Exploit
- 2024-08-03 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20221215-0010 | Third Party Advisory |
|
URL | Date | SRC |
---|---|---|
https://github.com/SpindleSec/cve-2022-31692 | 2024-08-12 | |
https://github.com/hotblac/cve-2022-31692 | 2023-10-29 | |
https://github.com/blipzip/cve-2022-31692 | 2025-02-09 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tanzu.vmware.com/security/cve-2022-31692 | 2023-08-08 | |
https://access.redhat.com/security/cve/CVE-2022-31692 | 2023-06-29 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2162206 | 2023-06-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Spring Security Search vendor "Vmware" for product "Spring Security" | >= 5.6.0 < 5.6.9 Search vendor "Vmware" for product "Spring Security" and version " >= 5.6.0 < 5.6.9" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring Security Search vendor "Vmware" for product "Spring Security" | >= 5.7.0 < 5.7.5 Search vendor "Vmware" for product "Spring Security" and version " >= 5.7.0 < 5.7.5" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Active Iq Unified Manager Search vendor "Netapp" for product "Active Iq Unified Manager" | - | vmware_vsphere |
Affected
| ||||||
Netapp Search vendor "Netapp" | Active Iq Unified Manager Search vendor "Netapp" for product "Active Iq Unified Manager" | - | windows |
Affected
|