The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2025-22234/ |
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-22 21:15
Updated : 2026-01-26 15:04
NVD link : CVE-2025-22234
Mitre link : CVE-2025-22234
CVE.ORG link : CVE-2025-22234
JSON object : View
Products Affected
No product.
CWE
CWE-208
Observable Timing Discrepancy
