Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an authorization bypass. Your application may be affected by this if the following are true: * You are using @EnableMethodSecurity(mode=ASPECTJ) and spring-security-aspects, and * You have Spring Security method annotations on a private method In that case, the target method may be able to be invoked without proper authorization. You are not affected if: * You are not using @EnableMethodSecurity(mode=ASPECTJ) or spring-security-aspects, or * You have no Spring Security-annotated private methods
History

Thu, 22 May 2025 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 21 May 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 21 May 2025 10:45:00 +0000

Type Values Removed Values Added
Description Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an authorization bypass. Your application may be affected by this if the following are true: * You are using @EnableMethodSecurity(mode=ASPECTJ) and spring-security-aspects, and * You have Spring Security method annotations on a private method In that case, the target method may be able to be invoked without proper authorization. You are not affected if: * You are not using @EnableMethodSecurity(mode=ASPECTJ) or spring-security-aspects, or * You have no Spring Security-annotated private methods
Title CVE-2025-41232: Spring Security authorization bypass for method security annotations on private methods
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published: 2025-05-21T10:23:07.078Z

Updated: 2025-05-22T03:55:15.247Z

Reserved: 2025-04-16T09:29:46.972Z

Link: CVE-2025-41232

cve-icon Vulnrichment

Updated: 2025-05-21T13:48:09.087Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-21T12:16:21.993

Modified: 2025-05-21T20:24:58.133

Link: CVE-2025-41232

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-05-21T10:23:07Z

Links: CVE-2025-41232 - Bugzilla