CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-22234

Medium Severity
SVRS
30/100

CVSSv3
NA/10

EPSS
0.0121/1

CVE-2024-22234 is a Spring Security vulnerability leading to broken access control when AuthenticationTrustResolver.isFullyAuthenticated(Authentication) is used directly with a null authentication parameter. This results in an incorrect true return value, potentially granting unauthorized access. Despite a CVSS score of 0, the SOCRadar Vulnerability Risk Score (SVRS) is 30, highlighting the need for awareness. The vulnerability exists in Spring Security versions 6.1.x before 6.1.7 and 6.2.x before 6.2.2. Applications are only vulnerable if they directly utilize AuthenticationTrustResolver.isFullyAuthenticated(Authentication) and pass null to it. The risk associated with CVE-2024-22234 includes potential unauthorized access and data breaches if exploited. Immediate action may not be required based on SVRS and CVSS scores.

In The Wild
Exploit Avaliable
2024-02-20

2025-02-13
Eye Icon
SOCRadar
AI Insight

.

Indicators of Compromise

No IOCs found for this CVE

Exploits

TitleSoftware LinkDate
nomi-sec/PoC-in-GitHubhttps://github.com/nomi-sec/PoC-in-GitHub2019-12-08
Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

No news found for this CVE

Social Media

No tweets found for this CVE

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://spring.io/security/cve-2024-22234
[email protected]https://security.netapp.com/advisory/ntap-20240315-0003/
[email protected]https://spring.io/security/cve-2024-22234
AF854A3A-2127-422B-91AE-364DA2661108https://security.netapp.com/advisory/ntap-20240315-0003/
AF854A3A-2127-422B-91AE-364DA2661108https://spring.io/security/cve-2024-22234
[email protected]https://security.netapp.com/advisory/ntap-20240315-0003/
[email protected]https://spring.io/security/cve-2024-22234

CWE Details

CWE IDCWE NameDescription
CWE-284Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence