Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2022-31692: Spring Security Core may let attackers bypass protections
CVE-2022-31692 · published today
Summary
The Spring Security Core library used in several applications can be tricked into bypassing security checks, potentially letting unauthorized users access data or functions. This affects products that include the spring-security-core component, such as Spring Framework, VMware Spring Security, NetApp Active IQ Unified Manager, and Root’s own packages. Apply the latest updated version of the library as soon as possible to close the gap.
What to do
- Update springframework org.springframework.security:spring-security-core to version 5.7.5.
- Update springframework org.springframework.security:spring-security-core to version 5.6.9.
- Update root io.root.org.springframework.security:spring-security-core to version 5.7.1-root.io.3.
- Update root io.root.org.springframework.security:spring-security-core to version 5.7.3-root.io.4.
- Update springframework org.springframework.security:spring-security-core to version 5.7.3-aikido.4.
- Update root io.root.org.springframework.security:spring-security-core to version 5.7.1-root.io.4.
- Update springframework org.springframework.security:spring-security-core to version 5.7.1-aikido.4.
- Update org.springframework.security:spring-security-core to version 5.7.5-aikido.1.
- Update io.root.org.springframework.security:spring-security-core to version 5.7.5-root.io.1.
- Update root io.root.org.springframework.security:spring-security-core to version 5.7.1-root.io.1.
- Update springframework org.springframework.security:spring-security-core to version 5.7.1-aikido.3.
- Update springframework org.springframework.security:spring-security-core to version 5.7.3-aikido.3.
- Update springframework org.springframework.security:spring-security-core to version 5.7.3-aikido.5.
- Update root io.root.org.springframework.security:spring-security-core to version 5.7.3-root.io.3.
- Update root io.root.org.springframework.security:spring-security-core to version 5.7.3-root.io.5.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| maven | springframework | org.springframework.security:spring-security-core |
>= 5.7.0, < 5.7.5 >= 5.6.0, < 5.6.9 Fix: upgrade to 5.7.5
|
| – | vmware | spring_security |
>= 5.6.0, < 5.6.9 >= 5.7.0, < 5.7.5 cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* |
| – | netapp | active_iq_unified_manager |
All versions
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* |
| Root:Maven | root | io.root.org.springframework.security:spring-security-core |
< 5.7.1-root.io.3 < 5.7.3-root.io.4 < 5.7.1-root.io.4 < 5.7.1-root.io.1 < 5.7.3-root.io.3 < 5.7.3-root.io.5 Fix: upgrade to 5.7.1-root.io.3
|
| Root:Maven | springframework | org.springframework.security:spring-security-core |
< 5.7.3-aikido.4 < 5.7.1-aikido.4 < 5.7.1-aikido.3 < 5.7.3-aikido.3 < 5.7.3-aikido.5 Fix: upgrade to 5.7.3-aikido.4
|
| Root:Maven | – | org.springframework.security:spring-security-core |
< 5.7.5-aikido.1 Fix: upgrade to 5.7.5-aikido.1
|
| Root:Maven | – | io.root.org.springframework.security:spring-security-core |
< 5.7.5-root.io.1 Fix: upgrade to 5.7.5-root.io.1
|
Original advisory text
CVE-2022-31692 in org.springframework.security:spring-security-core - Patched by Root
Root has patched CVE-2022-31692 in the org.springframework.security:spring-security-core package for Root:Maven. Multiple fixed versions available.
Severity
9.8
Critical
CVSS 3.1: 9.8 (GHSA)
Exploitation
EPSS 4%
Type
CWE-863Incorrect Authorization
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published22 Sep 2026
Updated22 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta