cognitive cybersecurity intelligence

News and Analysis

Search

Spring Security Vulnerability Let Attackers Determine Which Usernames are Valid

Spring Security Vulnerability Let Attackers Determine Which Usernames are Valid

A vulnerability (CVE-2025-22234) in various Spring Security versions allows attackers to exploit timing attacks to determine valid usernames, jeopardizing user enumeration defenses. Affected versions include 5.7.16 and 6.4.4. Mitigations include upgrading to patched versions or seeking commercial support. The flaw, discovered by Jonas Robl, is rated Medium severity. Patches are available via HeroDevs’ support.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts