Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jrg-rf5x-568g

Опубликовано: 22 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.

Пакеты

Наименование

org.springframework.security:spring-security-web

maven
Затронутые версииВерсия исправления

>= 7.0.0, <= 7.0.4

7.0.5

EPSS

Процентиль: 22%
0.00296
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-297

Связанные уязвимости

CVSS3: 6.8
ubuntu
3 месяца назад

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.

CVSS3: 8.1
redhat
3 месяца назад

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.

CVSS3: 6.8
nvd
3 месяца назад

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.

CVSS3: 6.8
debian
3 месяца назад

Vulnerability in Spring Spring Security.SubjectX500PrincipalExtractord ...

EPSS

Процентиль: 22%
0.00296
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-297