Database Management
DPA and the potential for a security bypass: CVE-2023-34034
The article explains why DPA is not affected by CVE-2023-34034.
First published date
Last published date
Overview
In August of 2023, the National Institute of Standards and Technology (NIST) updated the following security bulletin about the potential for a security bypass:
-
CVE-2023-34034 (© 2023 National Institute of Standards and Technology, available at nvd.nist.gov, obtained on November 12, 2023)
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
Product section
Cause
CVE-2023-34034
Resolution
Supported versions of DPA include an affected version of the spring-security-config library. However, this vulnerability does not apply to DPA. To be affected, an application must include both the spring-security-config library and the spring-webflux library, and DPA does not include the spring-webflux library.