spring-data-rest-core is vulnerable to Improper Access Control
71
High Risk
spring-data-rest-core does not block mutation of @Id and @Version properties on RFC 6902 JSON Patch requests. PUT and merge-patch skip those properties, but JSON Patch does not. An authenticated client with PATCH access can overwrite the identifier or version, defeating optimistic locking or overwriting another principal's record. The patch applies the same identifier and version guards to JSON Patch.
You are affected if you are using a version that falls within the vulnerable range and a Spring Data REST repository exposes @Id or @Version properties to Jackson and accepts JSON Patch.
spring-data-rest-core is vulnerable to Improper Access Control in versions 0.0.1 - 5.0.6 and 5.1.0 - 5.1.0.
Upgrade the org.springframework.data:spring-data-rest-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant