Authentication Bypass by Spoofing
CVE-2025-22223
Summary
The spring security versions 6.4.0-M2 through 6.4.3, and 6.5.0-M1 through 6.5.0-M2 may not correctly locate method security annotations on parameterized types or methods, potentially leading to an authorization bypass. Users are not affected if they are not using "@EnableMethodSecurity", if they do not have method security annotations on parameterized types or methods, or if all method security annotations are attached directly to the target methods.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- LOW
- NONE
CWE-290 - Authentication Bypass by Spoofing
This attack-focused weakness is caused by improperly implemented authentication schemes that are subject to spoofing attacks.
Advisory Timeline
- Published