org.springframework.security:spring-security-config@6.1.3 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.springframework.security:spring-security-config package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Incorrect Permission Assignment for Critical Resource

org.springframework.security:spring-security-config is a security configuration package for Spring Framework.

Affected versions of this package are vulnerable to Incorrect Permission Assignment for Critical Resource via the spring-security.xsd file due to being world writable. An attacker with access to the file system could extract this file and modify it.

How to fix Incorrect Permission Assignment for Critical Resource?

Upgrade org.springframework.security:spring-security-config to version 5.7.11, 5.8.7, 6.0.7, 6.1.4 or higher.

[5.7.9,5.7.11) [5.8.4,5.8.7) [6.0.4,6.0.7) [6.1.1,6.1.4)