Incorrect Permission Assignment for Critical Resource Affecting org.springframework.security:spring-security-config package, versions [5.7.9,5.7.11)[5.8.4,5.8.7)[6.0.4,6.0.7)[6.1.1,6.1.4)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (5th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-5905484
  • published19 Sept 2023
  • disclosed18 Sept 2023
  • creditMartin Holland

Introduced: 18 Sep 2023

CVE-2023-34042  (opens in a new tab)
CWE-732  (opens in a new tab)

How to fix?

Upgrade org.springframework.security:spring-security-config to version 5.7.11, 5.8.7, 6.0.7, 6.1.4 or higher.

Overview

org.springframework.security:spring-security-config is a security configuration package for Spring Framework.

Affected versions of this package are vulnerable to Incorrect Permission Assignment for Critical Resource via the spring-security.xsd file due to being world writable. An attacker with access to the file system could extract this file and modify it.

CVSS Scores

version 3.1