Skip to content

[CVE-2025-22235] HIGH: spring-boot 3.3.7 - EndpointRequest.to() wrong matcher #84

@nthmost-orkes

Description

@nthmost-orkes

Vulnerability Report

Field Value
CVE CVE-2025-22235
Severity HIGH
Library org.springframework.boot:spring-boot
Source workers.jar
Installed Version 3.3.7
Fixed Version 3.3.11, 3.4.5

Summary

Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed.

References


Filed from container vulnerability scan of workers.jar

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity-related issuesvulnerabilityDependency vulnerability

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions