9.8
CVSSv3

CVE-2022-22978

Published: 19/05/2022 Updated: 11/04/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 676
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In spring security versions before 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware spring security

oracle financial services crime and compliance management studio 8.0.8.2.0

oracle financial services crime and compliance management studio 8.0.8.3.0

netapp active iq unified manager -

Vendor Advisories

Synopsis Important: jenkins and jenkins-2-plugins security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for jenkins and jenkins-2-plugins is now available for OpenShift Developer Tools and Services for ...
Synopsis Important: Red Hat Fuse 7110 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 710 to 711) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security has rated this update ...

Github Repositories

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋 Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or code Specifically, you can view each vuln

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋 Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or code Specifically, you can view each vuln

CVE 2022-22978: Authorization Bypass in RegexRequestMatcher 🥶 Khái quát Theo thông tin em tìm hiểu được, đây là lỗ hổng liên quan đến class RegexRequestMatcher trong framework Spring Security Cụ thể, những application sử dụng RegexRequestMatcher mà trong regular expression có chứa dấu ch

Java web common vulnerabilities and security code which is base on springboot and spring security

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋 Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or code Specifically, you can view each vuln

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋Alibaba Security Purple Team Recruitment Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or co

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋Alibaba Security Purple Team Recruitment Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or co

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋Alibaba Security Purple Team Recruitment Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or co

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋Alibaba Security Purple Team Recruitment Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or co

CVE-2022-22978 POC Project

CVE-2022-22978 Spring Security Pass Spring Security (成功) localhost:9090/login%0a Pass Spring Security with SayMyName (失敗) localhost:9090/name%0d Bypass Spring Security with Custom RBAC (失敗) localhost:9090/admin/admin%0d Bypass Spring Security with Annotation RBAC (失敗) localhost:9090/user/user%0a

spring-security-CVE-2022-22978-Jar The full code is in this repo -> githubcom/mukeshkumar286/spring-security-CVE-2022-22978 This repo only has the spring security core jar for faster pull

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋 Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or code Specifically, you can view each vuln

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋Alibaba Security Purple Team Recruitment Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or co

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋Alibaba Security Purple Team Recruitment Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or co

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋Alibaba Security Purple Team Recruitment Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or co

CVE-2022-22978 Spring-Security bypass Demo

CVE-2022-22978 Spring-Security bypass Demo 在Spring Security中使用RegexRequestMatcher且规则中包含带点号的正则表达式时,攻击者可以通过构造恶意数据包绕过身份认证 影响范围 Spring Security 55x < 557 Spring Security 56x < 564 复现 Paylaod localhost:8080/admin/index%0a Docker docker pull s0cke3t/cve-

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋 Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or code Specifically, you can view each vuln

CVE-2022-32532 about This is a demo project, which only shows one of the conditions for exploiting this vulnerability (CVE-2022-32532) In fact, there are more ways to exploit it, as long as developers use RegExPatternMatcher, there will be a possible bypass vulnerability introduce Token request header verification is required under the current configuration, otherwise you do

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋Alibaba Security Purple Team Recruitment Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerabilit

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋Alibaba Security Purple Team Recruitment Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or co

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋Alibaba Security Purple Team Recruitment Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or co

PoC of CVE-2022-22978 vulnerability in Spring Security framework

CVE 2022-22978: Authorization Bypass in RegexRequestMatcher 🥶 Khái quát Theo thông tin em tìm hiểu được, đây là lỗ hổng liên quan đến class RegexRequestMatcher trong framework Spring Security Cụ thể, những application sử dụng RegexRequestMatcher mà trong regular expression có chứa dấu ch

CVE 2022-22978: Authorization Bypass in RegexRequestMatcher 🥶 Khái quát Theo thông tin em tìm hiểu được, đây là lỗ hổng liên quan đến class RegexRequestMatcher trong framework Spring Security Cụ thể, những application sử dụng RegexRequestMatcher mà trong regular expression có chứa dấu ch

Apache Shiro CVE-2022-32532

CVE-2022-32532 about This is a demo project, which only shows one of the conditions for exploiting this vulnerability (CVE-2022-32532) In fact, there are more ways to exploit it, as long as developers use RegExPatternMatcher, there will be a possible bypass vulnerability introduce Token request header verification is required under the current configuration, otherwise you do

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋 Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or code Specifically, you can view each vuln

Java Sec Code Java sec code is a very powerful and friendly project for learning Java vulnerability code 中文文档 😋 Introduce This project can also be called Java vulnerability code Each vulnerability type code has a security vulnerability by default unless there is no vulnerability The relevant fix code is in the comments or code Specifically, you can view each vuln