VYPR
Medium severity5.3NVD Advisory· Published Oct 28, 2021· Updated Jun 17, 2026

CVE-2021-22047

CVE-2021-22047

Description

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.springframework.data:spring-data-rest-coreMaven
>= 3.4.0, < 3.4.143.4.14
org.springframework.data:spring-data-rest-coreMaven
>= 3.5.0, < 3.5.63.5.6

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.