Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x873-6rgc-94jc

Опубликовано: 19 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.3

Описание

Spring Security logout not clearing security context

In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the HttpSessionSecurityContextRepository. This vulnerability can keep users authenticated even after they performed logout. Users of affected versions should apply the following mitigation. 5.7.x users should upgrade to 5.7.8. 5.8.x users should upgrade to 5.8.3. 6.0.x users should upgrade to 6.0.3.

Пакеты

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 5.7.0, < 5.7.8

5.7.8

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 5.8.0, < 5.8.3

5.8.3

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.0.3

6.0.3

EPSS

Процентиль: 58%
0.00372
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-459

Связанные уязвимости

CVSS3: 6.3
redhat
почти 3 года назад

In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the HttpSessionSecurityContextRepository. This vulnerability can keep users authenticated even after they performed logout. Users of affected versions should apply the following mitigation. 5.7.x users should upgrade to 5.7.8. 5.8.x users should upgrade to 5.8.3. 6.0.x users should upgrade to 6.0.3.

CVSS3: 6.3
nvd
почти 3 года назад

In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the HttpSessionSecurityContextRepository. This vulnerability can keep users authenticated even after they performed logout. Users of affected versions should apply the following mitigation. 5.7.x users should upgrade to 5.7.8. 5.8.x users should upgrade to 5.8.3. 6.0.x users should upgrade to 6.0.3.

CVSS3: 9.8
fstec
почти 2 года назад

Уязвимость Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, связанная с неполной очисткой временных или вспомогательных ресурсов, позволяющая нарушителю получить доступ к конфиденциальным данным или вызвать отказ в обслуживании

EPSS

Процентиль: 58%
0.00372
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-459