Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2022-31692: Spring Security Core may let attackers bypass protections

CVE-2022-31692 · published today
Summary

The Spring Security Core library used in several applications can be tricked into bypassing security checks, potentially letting unauthorized users access data or functions. This affects products that include the spring-security-core component, such as Spring Framework, VMware Spring Security, NetApp Active IQ Unified Manager, and Root’s own packages. Apply the latest updated version of the library as soon as possible to close the gap.

What to do
  • Update springframework org.springframework.security:spring-security-core to version 5.7.5.
  • Update springframework org.springframework.security:spring-security-core to version 5.6.9.
  • Update root io.root.org.springframework.security:spring-security-core to version 5.7.1-root.io.3.
  • Update root io.root.org.springframework.security:spring-security-core to version 5.7.3-root.io.4.
  • Update springframework org.springframework.security:spring-security-core to version 5.7.3-aikido.4.
  • Update root io.root.org.springframework.security:spring-security-core to version 5.7.1-root.io.4.
  • Update springframework org.springframework.security:spring-security-core to version 5.7.1-aikido.4.
  • Update org.springframework.security:spring-security-core to version 5.7.5-aikido.1.
  • Update io.root.org.springframework.security:spring-security-core to version 5.7.5-root.io.1.
  • Update root io.root.org.springframework.security:spring-security-core to version 5.7.1-root.io.1.
  • Update springframework org.springframework.security:spring-security-core to version 5.7.1-aikido.3.
  • Update springframework org.springframework.security:spring-security-core to version 5.7.3-aikido.3.
  • Update springframework org.springframework.security:spring-security-core to version 5.7.3-aikido.5.
  • Update root io.root.org.springframework.security:spring-security-core to version 5.7.3-root.io.3.
  • Update root io.root.org.springframework.security:spring-security-core to version 5.7.3-root.io.5.
Affected software
Ecosystem VendorProductAffected versions
maven springframework org.springframework.security:spring-security-core >= 5.7.0, < 5.7.5
>= 5.6.0, < 5.6.9
Fix: upgrade to 5.7.5
vmware spring_security >= 5.6.0, < 5.6.9
>= 5.7.0, < 5.7.5
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
netapp active_iq_unified_manager All versions
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
Root:Maven root io.root.org.springframework.security:spring-security-core < 5.7.1-root.io.3
< 5.7.3-root.io.4
< 5.7.1-root.io.4
< 5.7.1-root.io.1
< 5.7.3-root.io.3
< 5.7.3-root.io.5
Fix: upgrade to 5.7.1-root.io.3
Root:Maven springframework org.springframework.security:spring-security-core < 5.7.3-aikido.4
< 5.7.1-aikido.4
< 5.7.1-aikido.3
< 5.7.3-aikido.3
< 5.7.3-aikido.5
Fix: upgrade to 5.7.3-aikido.4
Root:Maven org.springframework.security:spring-security-core < 5.7.5-aikido.1
Fix: upgrade to 5.7.5-aikido.1
Root:Maven io.root.org.springframework.security:spring-security-core < 5.7.5-root.io.1
Fix: upgrade to 5.7.5-root.io.1
Original advisory text
CVE-2022-31692 in org.springframework.security:spring-security-core - Patched by Root
Root has patched CVE-2022-31692 in the org.springframework.security:spring-security-core package for Root:Maven. Multiple fixed versions available.
Severity
9.8 Critical
CVSS 3.1: 9.8 (GHSA)
Exploitation
EPSS 4%
Type
CWE-863Incorrect Authorization
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published22 Sep 2026
Updated22 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta