Red Hat Bugzilla – Bug 1578582
CVE-2018-1258 spring-security-core: Unauthorized Access with Spring Security Method Security
Last modified: 2018-07-18 11:59:27 EDT
A flaw was found in Spring Security in combination with Spring Framework versions prior to 5.0.6 contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. References: https://pivotal.io/security/cve-2018-1258
Created springframework-security tracking bugs for this issue: Affects: fedora-all [bug 1578937]
Updating the flaw description: A flaw was found in Spring Security in combination with Spring Framework version 5.0.5.RELEASE only, contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.