---
title: "CVE-2024-22257: Possible Broken Access Control in Spring Security With Direct Use of AuthenticatedVoter"
url: https://daily.dev/posts/cve-2024-22257-possible-broken-access-control-in-spring-security-with-direct-use-of-authenticatedvo-wbs8ugya7
source_url: https://spring.io/security/cve-2024-22257
type: article
source: "Spring"
published: 2024-03-18T13:55:29.144Z
updated: 2024-05-09T08:58:27.770Z
tags: ["security", "authentication", "vulnerability", "spring-security"]
reading_time: 1
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CVE-2024-22257: Possible Broken Access Control in Spring Security With Direct Use of AuthenticatedVoter

**[Spring](https://daily.dev/sources/spring)** · 1 min read · 1 upvotes · 0 comments

## Summary

A vulnerability in Spring Security allows for broken access control when using the AuthenticatedVoter with a null authentication parameter.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://spring.io/security/cve-2024-22257>

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 0 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#authentication](https://daily.dev/tags/authentication), [#vulnerability](https://daily.dev/tags/vulnerability), [#spring-security](https://daily.dev/tags/spring-security)

[View this post on daily.dev](https://daily.dev/posts/cve-2024-22257-possible-broken-access-control-in-spring-security-with-direct-use-of-authenticatedvo-wbs8ugya7)
