{"id":"CVE-2021-22047","aliases":["GHSA-4926-qpxg-6r3w"],"url":"https://o3.security/vulnerability/CVE-2021-22047","summary":"Exposure of Resource to Wrong Sphere in Spring Data REST","details":"In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.","published":"2021-10-28T16:15:07.623Z","modified":"2026-07-09T00:12:36.121481Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.springframework.data:spring-data-rest-core","fixedVersion":"3.4.14"},{"ecosystem":"Maven","name":"org.springframework.data:spring-data-rest-core","fixedVersion":"3.5.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://tanzu.vmware.com/security/cve-2021-22047"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:12:36.121481Z"}}