spring-security-core is vulnerable to Improper Input Validation
37
Low Risk
spring-security-core InetAddressMatchers does not treat IPv4 and IPv6 any-local addresses (0.0.0.0 and ::) as internal. matchExternal() therefore classifies them as external and matchInternal() fails to match them. Access-control rules that should treat those addresses as internal can make the wrong decision. The patch classifies any-local addresses as internal.
You are affected if you are using a version that falls within the vulnerable range and you use InetAddressMatchers.matchInternal() or matchExternal() for access control involving 0.0.0.0 or ::.
spring-security-core is vulnerable to Improper Input Validation in versions 7.1.0 - 7.1.0.
Upgrade the org.springframework.security:spring-security-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant