Vigilance.fr - Spring Security: user access via AuthenticationTrustResolver.isFullyAuthenticated(), analyzed on 17/07/2024
April 2025 by Vigilance.fr
An attacker can bypass restrictions of Spring Security, via AuthenticationTrustResolver.isFullyAuthenticated(), in order to gain user privileges.
Plus d'information sur : https://vigilance.fr/vulnerability/Spring-Security-user-access-via-AuthenticationTrustResolver-isFullyAuthenticated-44768