« Volver al listado

CVE-2025-22235

Estado: AplazadaAlta (7.3)—

EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed.

Your application may be affected by this if all the following conditions are met:

You are not affected if any of the following is true:

Detalles técnicos trazas, registros y código del informe original
  *  You use Spring Security
  *  EndpointRequest.to() has been used in a Spring Security chain configuration
  *  The endpoint which EndpointRequest references is disabled or not exposed via web
  *  Your application handles requests to /null and this path needs protection

  *  You don't use Spring Security
  *  You don't use EndpointRequest.to()
  *  The endpoint which EndpointRequest.to() refers to is enabled and is exposed
  *  Your application does not handle requests to /null or this path does not need protection

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Red sin autenticación (AV:N/PR:N/UI:N) explotando bypass de autenticación en Spring Security vía EndpointRequest.to() cuando el endpoint está deshabilitado; impacto: manipulación de datos y acceso a información sensible (C:L/I:L).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-22235",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-22235",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-28T16:16:38.622106Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Spring Boot",
          "versions": [
            {
              "status": "affected",
              "version": "2.7.x",
              "lessThan": "2.7.25",
              "versionType": "Enterprise Support Only"
            },
            {
              "status": "affected",
              "version": "3.1.x",
              "lessThan": "3.1.16",
              "versionType": "Enterprise Support Only"
            },
            {
              "status": "affected",
              "version": "3.2.x",
              "lessThan": "3.2.14",
              "versionType": "Enterprise Support Only"
            },
            {
              "status": "affected",
              "version": "3.3.x",
              "lessThan": "3.3.11",
              "versionType": "OSS"
            },
            {
              "status": "affected",
              "version": "3.4.x",
              "lessThan": "3.4.5",
              "versionType": "OSS"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-04-28T08:15:15.273",
  "references": [
    {
      "url": "https://spring.io/security/cve-2025-22235",
      "source": "security@vmware.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20250516-0010/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@vmware.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed.\n\nYour application may be affected by this if all the following conditions are met:\n\n  *  You use Spring Security\n  *  EndpointRequest.to() has been used in a Spring Security chain configuration\n  *  The endpoint which EndpointRequest references is disabled or not exposed via web\n  *  Your application handles requests to /null and this path needs protection\n\n\nYou are not affected if any of the following is true:\n\n  *  You don't use Spring Security\n  *  You don't use EndpointRequest.to()\n  *  The endpoint which EndpointRequest.to() refers to is enabled and is exposed\n  *  Your application does not handle requests to /null or this path does not need protection"
    },
    {
      "lang": "es",
      "value": "EndpointRequest.to() crea un comparador para null/** si el endpoint del actuador, para el que se creó EndpointRequest, está deshabilitado o no está expuesto. Su aplicación puede verse afectada si se cumplen todas las siguientes condiciones: * Utiliza Spring Security * EndpointRequest.to() se ha utilizado en una configuración de cadena de Spring Security * El punto final al que EndpointRequest hace referencia está deshabilitado o no está expuesto a través de la web * Su aplicación gestiona solicitudes a /null y esta ruta necesita protección no se verá afectado si se cumple alguna de las siguientes condiciones: * No utiliza Spring Security * No utiliza EndpointRequest.to() * El endpoint al que EndpointRequest.to() hace referencia está habilitado y está expuesto * Su aplicación no gestiona solicitudes a /null o esta ruta no necesita protección"
    }
  ],
  "lastModified": "2026-06-17T08:45:48.460",
  "sourceIdentifier": "security@vmware.com"
}