Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
affected
5.7.16 (semver)
affected
5.8.18 (semver)
affected
6.0.16 (semver)
affected
6.1.14 (semver)
affected
6.2.10 (semver)
affected
6.3.8 (semver)
affected
6.4.4 (semver)
affected
Description
The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.
Problem types
Product status
5.7.16 (semver)
5.8.18 (semver)
6.0.16 (semver)
6.1.14 (semver)
6.2.10 (semver)
6.3.8 (semver)
6.4.4 (semver)
Credits
Jonas Robl
References
spring.io/security/cve-2025-22234/ (Spring Security Advisory: CVE-2025-22234)