{"id":"CVE-2023-20873","aliases":["GHSA-g5h3-w546-pj7f"],"url":"https://o3.security/vulnerability/CVE-2023-20873","summary":"Spring Boot Security Bypass with Wildcard Pattern Matching on Cloud Foundry","details":"In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to 2.7.11+. Users of older, unsupported versions should upgrade to 3.0.6+ or 2.7.11+.","published":"2023-04-20T00:00:00Z","modified":"2026-08-12T03:51:29.833596062Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01122,"percentile":0.64619,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.springframework.boot:spring-boot-actuator-autoconfigure","fixedVersion":"3.0.6"},{"ecosystem":"Maven","name":"org.springframework.boot:spring-boot-actuator-autoconfigure","fixedVersion":"2.7.11"},{"ecosystem":"Maven","name":"org.springframework.boot:spring-boot-actuator-autoconfigure","fixedVersion":"2.6.15"},{"ecosystem":"Maven","name":"org.springframework.boot:spring-boot-actuator-autoconfigure","fixedVersion":"2.5.15"}],"fix":{"url":"https://github.com/spring-projects/spring-boot/commit/32444fed4b51cc58dc908467f706102d7f0bfc15","label":"spring-projects/spring-boot@32444fe"},"references":[{"type":"WEB","url":"https://spring.io/security/cve-2023-20873"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/20xxx/CVE-2023-20873.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-20873"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230601-0009/"},{"type":"ARTICLE","url":"https://spring.io/blog/2023/05/18/spring-boot-2-5-15-and-2-6-15-available-now"},{"type":"WEB","url":"https://github.com/spring-projects/spring-boot/commit/32444fed4b51cc58dc908467f706102d7f0bfc15"},{"type":"WEB","url":"https://github.com/spring-projects/spring-boot/commit/3522714c13b47af03bf42e7f2d5994af568cb1a7"},{"type":"PACKAGE","url":"https://github.com/spring-projects/spring-boot"},{"type":"WEB","url":"https://github.com/spring-projects/spring-boot/releases/tag/v2.5.15"},{"type":"WEB","url":"https://github.com/spring-projects/spring-boot/releases/tag/v2.6.15"},{"type":"WEB","url":"https://github.com/spring-projects/spring-boot/releases/tag/v2.7.11"},{"type":"WEB","url":"https://github.com/spring-projects/spring-boot/releases/tag/v3.0.6"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230601-0009"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:29.833596062Z"}}