GHSA-3295-h9qx-r82x
Dashboard / Vulnerabilities / GHSA-3295-h9qx-r82x
Summary: Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi Security
Details: VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
References: https://nvd.nist.gov/vuln/detail/CVE-2010-3700, https://issues.apache.org/bugzilla/show_bug.cgi?id=25015, https://web.archive.org/web/20110802082343/http://www.springsource.com/security/cve-2010-3700
Affected packages
Package
Name: org.springframework.security:spring-security-core
Purl: pkg:maven/org.springframework.security/spring-security-core
Affected ranges
Type: ECOSYSTEM
Events:
