{"id":"CVE-2016-5007","details":"Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching mechanisms, for example with regards to space trimming in path segments, can lead Spring Security to not recognize certain paths as not protected that are in fact mapped to Spring MVC controllers that should be protected. The problem is compounded by the fact that the Spring Framework provides richer features with regards to pattern matching as well as by the fact that pattern matching in each Spring Security and the Spring Framework can easily be customized creating additional differences.","aliases":["GHSA-8crv-49fr-2h6j"],"modified":"2026-07-07T08:46:10.278126440Z","published":"2017-05-25T17:29:00.740Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:pivotal_software:spring_framework:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:spring_framework:4.0.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:spring_framework:4.1.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:spring_framework:4.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.2.0"},{"last_affected":"3.2.0"},{"introduced":"4.0.0"},{"last_affected":"4.0.0"},{"introduced":"4.1.0"},{"last_affected":"4.1.0"},{"introduced":"4.2.0"},{"last_affected":"4.2.0"}],"source":"CPE_STRING","vendor_product":"pivotal_software:spring_framework"}]},"references":[{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/91687"},{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2016-5007"},{"type":"ADVISORY","url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/spring-projects/spring-framework","events":[{"introduced":"234cb84e832da30b6f53ccca4ef28043aacfcecc"},{"last_affected":"2cc3b278024ca45a72bc847a9457fc138424b16c"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:vmware:spring_framework:3.2.1:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.3:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.4:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.5:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.6:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.7:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.8:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.9:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.10:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.11:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.12:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.13:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.14:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.15:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.16:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.17:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:3.2.18:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.0.1:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.0.2:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.0.3:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.0.4:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.0.5:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.0.6:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.0.7:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.0.8:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.0.9:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.1.1:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.1.2:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.1.3:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.1.4:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.1.5:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.1.6:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.1.7:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.1.8:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.1.9:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.2.1:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.2.2:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.2.3:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.2.4:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.2.5:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.2.6:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.2.7:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.2.8:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_framework:4.2.9:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.2.1"},{"last_affected":"3.2.1"},{"introduced":"3.2.2"},{"last_affected":"3.2.2"},{"introduced":"3.2.3"},{"last_affected":"3.2.3"},{"introduced":"3.2.4"},{"last_affected":"3.2.4"},{"introduced":"3.2.5"},{"last_affected":"3.2.5"},{"introduced":"3.2.6"},{"last_affected":"3.2.6"},{"introduced":"3.2.7"},{"last_affected":"3.2.7"},{"introduced":"3.2.8"},{"last_affected":"3.2.8"},{"introduced":"3.2.9"},{"last_affected":"3.2.9"},{"introduced":"3.2.10"},{"last_affected":"3.2.10"},{"introduced":"3.2.11"},{"last_affected":"3.2.11"},{"introduced":"3.2.12"},{"last_affected":"3.2.12"},{"introduced":"3.2.13"},{"last_affected":"3.2.13"},{"introduced":"3.2.14"},{"last_affected":"3.2.14"},{"introduced":"3.2.15"},{"last_affected":"3.2.15"},{"introduced":"3.2.16"},{"last_affected":"3.2.16"},{"introduced":"3.2.17"},{"last_affected":"3.2.17"},{"introduced":"3.2.18"},{"last_affected":"3.2.18"},{"introduced":"4.0.1"},{"last_affected":"4.0.1"},{"introduced":"4.0.2"},{"last_affected":"4.0.2"},{"introduced":"4.0.3"},{"last_affected":"4.0.3"},{"introduced":"4.0.4"},{"last_affected":"4.0.4"},{"introduced":"4.0.5"},{"last_affected":"4.0.5"},{"introduced":"4.0.6"},{"last_affected":"4.0.6"},{"introduced":"4.0.7"},{"last_affected":"4.0.7"},{"introduced":"4.0.8"},{"last_affected":"4.0.8"},{"introduced":"4.0.9"},{"last_affected":"4.0.9"},{"introduced":"4.1.1"},{"last_affected":"4.1.1"},{"introduced":"4.1.2"},{"last_affected":"4.1.2"},{"introduced":"4.1.3"},{"last_affected":"4.1.3"},{"introduced":"4.1.4"},{"last_affected":"4.1.4"},{"introduced":"4.1.5"},{"last_affected":"4.1.5"},{"introduced":"4.1.6"},{"last_affected":"4.1.6"},{"introduced":"4.1.7"},{"last_affected":"4.1.7"},{"introduced":"4.1.8"},{"last_affected":"4.1.8"},{"introduced":"4.1.9"},{"last_affected":"4.1.9"},{"introduced":"4.2.1"},{"last_affected":"4.2.1"},{"introduced":"4.2.2"},{"last_affected":"4.2.2"},{"introduced":"4.2.3"},{"last_affected":"4.2.3"},{"introduced":"4.2.4"},{"last_affected":"4.2.4"},{"introduced":"4.2.5"},{"last_affected":"4.2.5"},{"introduced":"4.2.6"},{"last_affected":"4.2.6"},{"introduced":"4.2.7"},{"last_affected":"4.2.7"},{"introduced":"4.2.8"},{"last_affected":"4.2.8"},{"introduced":"4.2.9"},{"last_affected":"4.2.9"}]}}],"versions":["3.2.1","3.2.10","3.2.11","3.2.12","3.2.13","3.2.14","3.2.15","3.2.16","3.2.17","3.2.18","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.2.8","3.2.9","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.0.7","4.0.8","4.0.9","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.1.7","4.1.8","4.1.9","4.2.1","4.2.2","4.2.3","4.2.4","4.2.5","4.2.6","4.2.7","4.2.8","4.2.9"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-5007.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/spring-projects/spring-security","events":[{"introduced":"4619705e37fa49556480fb942247fb7b63727b3e"},{"last_affected":"001b05569af749a34daac9191014cf3e2658b018"}],"database_specific":{"cpe":["cpe:2.3:a:vmware:spring_security:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:3.2.1:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:3.2.3:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:3.2.4:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:3.2.5:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:3.2.6:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:3.2.7:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:3.2.8:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:3.2.9:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:3.2.10:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:4.0.0:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:4.0.1:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:4.0.2:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:4.0.3:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:4.0.4:*:*:*:*:*:*:*","cpe:2.3:a:vmware:spring_security:4.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.2.0"},{"last_affected":"3.2.0"},{"introduced":"3.2.1"},{"last_affected":"3.2.1"},{"introduced":"3.2.2"},{"last_affected":"3.2.2"},{"introduced":"3.2.3"},{"last_affected":"3.2.3"},{"introduced":"3.2.4"},{"last_affected":"3.2.4"},{"introduced":"3.2.5"},{"last_affected":"3.2.5"},{"introduced":"3.2.6"},{"last_affected":"3.2.6"},{"introduced":"3.2.7"},{"last_affected":"3.2.7"},{"introduced":"3.2.8"},{"last_affected":"3.2.8"},{"introduced":"3.2.9"},{"last_affected":"3.2.9"},{"introduced":"3.2.10"},{"last_affected":"3.2.10"},{"introduced":"4.0.0"},{"last_affected":"4.0.0"},{"introduced":"4.0.1"},{"last_affected":"4.0.1"},{"introduced":"4.0.2"},{"last_affected":"4.0.2"},{"introduced":"4.0.3"},{"last_affected":"4.0.3"},{"introduced":"4.0.4"},{"last_affected":"4.0.4"},{"introduced":"4.1.0"},{"last_affected":"4.1.0"}],"source":"CPE_STRING"}}],"versions":["3.2.0","3.2.1","3.2.10","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.2.8","3.2.9","4.0.0","4.0.1","4.0.2","4.0.3","4.0.4","4.1.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-5007.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}