GHSA-c4q5-6c82-3qpw · Severity: critical · Ecosystem: maven — Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all of the following must be true: * It must be a WebFlux application * It must be using Spring's static resources support * It must have a non-permitAll authorization rule applied to the static resources support
Conclusion & alert: CVE-2024-38821 is rated Moderate Risk (57.4/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.71%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 13.09% | 1.71% | -11.38% |
| 2 | 2026-03-19 | 10.08% | 13.09% | +3.01% |
| 3 | 2025-12-06 | — | 10.08% | — |
Full EPSS history (22 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | [email protected] |
GHSA-c4q5-6c82-3qpw · Severity: critical · Ecosystem: maven — Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2024-38821 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||