CVE-2018-1258
Executive Summary
CVE-2018-1258 exposes an authorization bypass in Spring Framework 5.0.5 when combined with any Spring Security version. The flaw allows an unauthenticated attacker to invoke methods protected by method‑level security, granting unauthorized access to sensitive functionality. The vulnerability is not currently listed in the CISA KEV database.
Authoritative CVE Metadata - CVSS Base Score: 8.8 (HIGH) - Published: 2018-05-11T20:29:00.260 - Last Modified: 2026-08-25T16:28:27.310
Original Description: Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
"These days people seek knowledge, not wisdom. Knowledge is of the past, wisdom is of the future."
— Vernon Cooper