Disabled Spring Security protections

Disabled Spring Security protections

Description

Settings such as csrf().disable(), frameOptions().disable() and anyRequest().permitAll() disable protections or access restrictions in the applicable Spring Security filter chain. The risk depends on automatically sent browser credentials, other framing restrictions and which requests the chain handles.

Potential impact

  • Without CSRF protection, an external site may trigger state changes when the browser automatically sends credentials such as cookies.
  • Disabling frameOptions may weaken clickjacking protection.
  • anyRequest().permitAll() does not require authentication for requests handled by that chain and may expose functions that should be protected.

Remediation

  • Review the browser authentication mechanism and retain CSRF protection. Explicitly exclude only endpoints that do not need it; csrf().disable() applies to the whole chain.
  • Use sameOrigin or a suitable CSP frame-ancestors policy instead of simply removing framing restrictions.
  • Permit only intended public routes and require authentication elsewhere.

Examples

These are Spring Security 6.x configuration excerpts. Register the configuration class and configure authentication separately, using the DSL appropriate to your installed version.

Before

java
import org.springframework.context.annotation.Bean;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;

public class UnsafeCsrfConfig {
    @Bean
    SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http.csrf().disable();
        return http.build();
    }
}

After

java
import org.springframework.context.annotation.Bean;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;

public class SafeSecurityConfig {
    @Bean
    SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .requestMatchers("/health").permitAll()
                .anyRequest().authenticated()
            );
        return http.build();
    }
}

Explanation:

  • Before: Disables CSRF protection in this filter chain.
  • After: Retains default CSRF protection, allows /health without authentication and requires authentication for other requests. Configure role- and object-level authorization separately.

Review other protection settings

Check framing restrictions and broad request permissions against the intended design. In both the Java and Kotlin DSLs, retain the necessary protections and allow only the intended public routes.

References