Database Management

DPA and the potential for a security bypass: CVE-2023-34034

The article explains why DPA is not affected by CVE-2023-34034.

First published date

11/12/2023 11:52 PM

Last published date

11/12/2023 11:52 PM

Overview

In August of 2023, the National Institute of Standards and Technology (NIST) updated the following security bulletin about the potential for a security bypass:

  • CVE-2023-34034 (© 2023 National Institute of Standards and Technology, available at nvd.nist.gov, obtained on November 12, 2023)

Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.

Product section

Database Performance Analyzer

Cause

CVE-2023-34034

Resolution

Supported versions of DPA include an affected version of the spring-security-config library. However, this vulnerability does not apply to DPA. To be affected, an application must include both the spring-security-config library and the spring-webflux library, and DPA does not include the spring-webflux library.