UNKNOWN Maven
Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi Security
GHSA-3295-h9qx-r82x · CVE-2010-3700
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
Ready to move
Start Securing
Free, no credit card | First findings in minutes