Skip to main content

Authentication Bypass by Spoofing

CVE-2025-22223

Severity Medium
Score 5.3/10

Summary

The spring security versions 6.4.0-M2 through 6.4.3, and 6.5.0-M1 through 6.5.0-M2 may not correctly locate method security annotations on parameterized types or methods, potentially leading to an authorization bypass. Users are not affected if they are not using "@EnableMethodSecurity", if they do not have method security annotations on parameterized types or methods, or if all method security annotations are attached directly to the target methods.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-290 - Authentication Bypass by Spoofing

This attack-focused weakness is caused by improperly implemented authentication schemes that are subject to spoofing attacks.

Advisory Timeline

  • Published