CVE-2022-31692
Spring Security authorization rules can be bypassed via forward or include dispatcher types
CVEs:CVE-2022-31692
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Spring Security authorization rules can be bypassed via forward or include dispatcher types
CVEs:CVE-2022-31692
spring-security-oauth2-client vulnerable to Privilege Escalation
CVEs:CVE-2022-31690
Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens
CVEs:CVE-2022-31684
Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens
CVEs:GHSA-7w4x-4h67-pgmv
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.