Description
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
Remediation
References
https://security.netapp.com/advisory/ntap-20230814-0008/
https://spring.io/security/cve-2023-34034
Related Vulnerabilities
CVE-2021-21692 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-10862 Vulnerability in maven package org.wildfly.core:wildfly-deployment-repository
CVE-2023-32995 Vulnerability in maven package io.jenkins.plugins:miniorange-saml-sp
CVE-2021-1628 Vulnerability in maven package org.mule.runtime:mule-core
CVE-2022-36912 Vulnerability in maven package org.jenkins-ci.plugins:openstack-heat