{"id":"GHSA-4926-qpxg-6r3w","summary":"Exposure of Resource to Wrong Sphere in Spring Data REST","details":"In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.","aliases":["CVE-2021-22047"],"modified":"2023-11-01T04:54:23.827286Z","published":"2022-05-24T19:19:03Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-06-22T18:29:53Z","nvd_published_at":"2021-10-28T16:15:00Z","cwe_ids":["CWE-668"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22047"},{"type":"WEB","url":"https://tanzu.vmware.com/security/cve-2021-22047"}],"affected":[{"package":{"name":"org.springframework.data:spring-data-rest-core","ecosystem":"Maven","purl":"pkg:maven/org.springframework.data/spring-data-rest-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.4.0"},{"fixed":"3.4.14"}]}],"versions":["3.4.0","3.4.1","3.4.10","3.4.11","3.4.12","3.4.13","3.4.2","3.4.3","3.4.4","3.4.5","3.4.6","3.4.7","3.4.8","3.4.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.4.13","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4926-qpxg-6r3w/GHSA-4926-qpxg-6r3w.json"}},{"package":{"name":"org.springframework.data:spring-data-rest-core","ecosystem":"Maven","purl":"pkg:maven/org.springframework.data/spring-data-rest-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.5.0"},{"fixed":"3.5.6"}]}],"versions":["3.5.0","3.5.1","3.5.2","3.5.3","3.5.4","3.5.5"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.5.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4926-qpxg-6r3w/GHSA-4926-qpxg-6r3w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}