Skip to content

[GHSA-mgvc-8q2h-5pgc] Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints#7218

Closed
yeikel wants to merge 1 commit intoyeikel/advisory-improvement-7218from
yeikel-GHSA-mgvc-8q2h-5pgc
Closed

[GHSA-mgvc-8q2h-5pgc] Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints#7218
yeikel wants to merge 1 commit intoyeikel/advisory-improvement-7218from
yeikel-GHSA-mgvc-8q2h-5pgc

Conversation

@yeikel
Copy link
Copy Markdown

@yeikel yeikel commented Mar 23, 2026

Updates

  • Affected products
  • Description

Comments
Improve description using data from https://spring.io/security/cve-2026-22733

@github-actions github-actions Bot changed the base branch from main to yeikel/advisory-improvement-7218 March 23, 2026 18:12
@helixplant
Copy link
Copy Markdown

Hi,
Thanks for the suggestion. We’re going to keep the current description as-is, since the advisory already links to https://spring.io/security/cve-2026-22733 in the references and there isn’t a clear benefit to changing the text.

@helixplant helixplant closed this Mar 25, 2026
@yeikel
Copy link
Copy Markdown
Author

yeikel commented Mar 25, 2026

Hi, Thanks for the suggestion. We’re going to keep the current description as-is, since the advisory already links to https://spring.io/security/cve-2026-22733 in the references and there isn’t a clear benefit to changing the text.

The benefit is to keep all the context in place which helps various tools that read the dependabot alerts directly

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants