Vulnerabilities > CVE-2023-40788 - Exposure of Resource to Wrong Sphere vulnerability in Bladex Springblade 3.2.0/3.6.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Common Weakness Enumeration (CWE)
References
- https://gist.github.com/kaliwin/89276ec7e97f9529c989bd77706c29c7
- https://gist.github.com/kaliwin/89276ec7e97f9529c989bd77706c29c7
- https://github.com/chillzhuang/SpringBlade
- https://github.com/chillzhuang/SpringBlade
- https://github.com/chillzhuang/SpringBlade/blob/master/blade-gateway/src/main/java/org/springblade/gateway/provider/AuthProvider.java
- https://github.com/chillzhuang/SpringBlade/blob/master/blade-gateway/src/main/java/org/springblade/gateway/provider/AuthProvider.java