CVE-2025-22223 - CVE House
Back to Database
Status published Medium CVE-2025-22223

Spring Security 6.4.0 - 6.4.3 may not correctly locate method...

Vulnerability Description

Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass.  You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-22223

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Spring Security
Vulnerable Versions:
6.4.0-6.4.3

Timeline

Official Publish: March 24th, 2025
Last Modified: March 24th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)