CVE-2024-38821 is an authorization-bypass vulnerability in Spring WebFlux static-resource handling. In affected applications, Spring Security authorization rules intended to protect static resources can be bypassed under certain circumstances, causing requests to evade a non-permitAll rule configured for those resources.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-38821, an authentication bypass vulnerability in the Spring Framework (specifically Spring Boot 3.3.4 with Spring Framework 6.1.13). The repository is structured into two main directories: 'safe' (a secure implementation) and 'vuln' (a vulnerable implementation). Each contains a Spring Boot application with similar structure, including Java source files, Gradle build files, Dockerfiles, and static resources. The exploit demonstrates that by sending a specially crafted HTTP request to the vulnerable application (using the --path-as-is option in curl), an attacker can bypass authentication controls and access protected resources. The key payload is a request to '/css/../secret/secret-file.txt', which, due to improper path normalization, is allowed through the unauthenticated '/css/**' path matcher, thus bypassing the intended authentication requirement for '/secret/**'. The PoC is operational and demonstrates the vulnerability, but does not provide a weaponized or automated attack tool. The main exploit capability is authentication bypass via crafted HTTP paths. The repository includes all necessary files to build and run both the vulnerable and safe applications using Docker, and provides clear instructions for reproducing the exploit.
This repository is a Kotlin-based Spring Boot WebFlux application designed to demonstrate CVE-2024-38821, a static resource access vulnerability. The project structure follows standard Spring Boot conventions, with main application code in 'src/main/kotlin', configuration in 'src/main/resources', and static resources in 'src/main/resources/static'. The core of the demonstration is in the 'SecurityConfig.kt' and 'RouterConfig.kt' files. 'SecurityConfig.kt' configures security rules, notably requiring authentication for access to '/css/**', '/index.html', '/secure/hello', and '/application.yaml', while permitting all other exchanges. 'RouterConfig.kt' defines a '/secure/hello' endpoint that returns a static message. The presence of 'application.yaml' in the static resources and its exposure via HTTP is significant, as it may demonstrate the vulnerability by allowing unauthorized access to sensitive configuration data if security is misconfigured. The repository does not contain a weaponized payload but serves as a proof-of-concept for the vulnerability. It is intended for demonstration and educational purposes, showing how improper security configuration in Spring WebFlux can lead to exposure of static resources and configuration files.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical authorization bypass vulnerability in Spring WebFlux that can allow a remote unauthenticated attacker to bypass Spring Security authorization rules for static resources, impacting confidentiality and integrity.
An authorization-bypass vulnerability in Spring Security for Spring WebFlux applications. It affects applications using Spring static-resource support where static resources are protected by a non-permitAll authorization rule.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.