REDHAT-BUG-2460489: High severity Spring Spring Security vulnerability
Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/"/> to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2460489?
The severity of REDHAT-BUG-2460489 is high with a score of 7.
What does REDHAT-BUG-2460489 affect?
REDHAT-BUG-2460489 affects Spring Spring Security configurations using the sec:intercept-url directive.
How do I fix REDHAT-BUG-2460489?
To fix REDHAT-BUG-2460489, ensure that the servlet path is properly included in the authorization rules by updating your security configuration.
What are the risks associated with REDHAT-BUG-2460489?
The risks associated with REDHAT-BUG-2460489 include unauthorized access to endpoints if the servlet path is not correctly matched.
When was REDHAT-BUG-2460489 published?
REDHAT-BUG-2460489 was published on April 22, 2026.