Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-2731

Опубликовано: 05 дек. 2012
Источник: debian
EPSS Низкий

Описание

Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libspring-security-2.0-javafixed2.0.7.RELEASE-1package
libspring-security-2.0-javano-dsasqueezepackage

EPSS

Процентиль: 66%
0.01246
Низкий

Связанные уязвимости

ubuntu
больше 13 лет назад

Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread.

redhat
почти 15 лет назад

Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread.

nvd
больше 13 лет назад

Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread.

github
около 4 лет назад

Concurrent Execution using Shared Resource with Improper Synchronization in Spring Security

EPSS

Процентиль: 66%
0.01246
Низкий