CVE-2024-22234
CVE-2024-22234 is a Spring Security vulnerability leading to broken access control when AuthenticationTrustResolver.isFullyAuthenticated(Authentication)
is used directly with a null
authentication parameter. This results in an incorrect true
return value, potentially granting unauthorized access. Despite a CVSS score of 0, the SOCRadar Vulnerability Risk Score (SVRS) is 30, highlighting the need for awareness. The vulnerability exists in Spring Security versions 6.1.x before 6.1.7 and 6.2.x before 6.2.2. Applications are only vulnerable if they directly utilize AuthenticationTrustResolver.isFullyAuthenticated(Authentication)
and pass null
to it. The risk associated with CVE-2024-22234 includes potential unauthorized access and data breaches if exploited. Immediate action may not be required based on SVRS and CVSS scores.
.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.