CVE-2025-22234 UNKNOWN

CVE-2025-22234

Published: 2026-01-22

Description

The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…