Spring Security - CVE-2023-34034

Spring WebFlux โ€“ CVE-2023-34034 โ€“ Write-Up and Proof-of-Concept

Spring Securityโ€™s newly released versions contain a fix for a broken access control vulnerability โ€“ CVE-2023-34034 โ€“ which was given a critical NVD severity (CVSS 9.8) and a high severity by Springโ€™s maintainers. Given the severe potential impact of the vulnerability on Spring WebFlux applications (that use Spring Security for authentication and access control), its โ€ฆ