Skip to content

[GHSA-mgvc-8q2h-5pgc] Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints - #9321

Open
shaked-seal wants to merge 1 commit into
shaked-seal/advisory-improvement-9321from
shaked-seal-GHSA-mgvc-8q2h-5pgc
Open

[GHSA-mgvc-8q2h-5pgc] Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints#9321
shaked-seal wants to merge 1 commit into
shaked-seal/advisory-improvement-9321from
shaked-seal-GHSA-mgvc-8q2h-5pgc

Conversation

@shaked-seal

Copy link
Copy Markdown

Updates

  • Affected products

Comments
spring-boot-actuator and spring-boot-actuator-autoconfigure hold the vulnerable code.
spring-boot-starter-actuator does not contain the vulnerable code:
https://github.com/spring-projects/spring-boot/tree/v3.5.12/spring-boot-project/spring-boot-starters/spring-boot-starter-actuator.

Sources:
https://security.snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-15701836
spring-projects/spring-boot@01fbede
spring-projects/spring-boot@6620dea
spring-projects/spring-boot@5a917d3

@github-actions
github-actions Bot changed the base branch from main to shaked-seal/advisory-improvement-9321 September 2, 2026 14:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant