Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreThe spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access to the file system.
While there are no known exploits, this is an example of “CWE-732: Incorrect Permission Assignment for Critical Resource” and could result in an exploit. Users should update to the latest version of Spring Security to mitigate any future exploits found around this issue.
Spring Security:
The following Spring Security versions contain fixes for this vulnerability:
This vulnerability was disclosed responsibly by Martin Holland - Oval Business Solutions
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy