CVE-2018-1258
Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass
8.8
HIGH
CVSS 3.1
EPSS 0.27%
Description
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
How to fix CVE-2018-1258
To remediate CVE-2018-1258, upgrade the affected package to a fixed version below.
- —upgrade to 5.0.6.RELEASE or later
Is CVE-2018-1258 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 5.0.5.RELEASE, < 5.0.6.RELEASE
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |