Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-22747

Опубликовано: 22 апр. 2026
Источник: nvd
CVSS3: 6.8
CVSS3: 8.1
EPSS Низкий

Описание

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.0.5 (исключая)

EPSS

Процентиль: 22%
0.00296
Низкий

6.8 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-297
CWE-295

Связанные уязвимости

CVSS3: 6.8
ubuntu
3 месяца назад

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.

CVSS3: 8.1
redhat
3 месяца назад

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.

CVSS3: 6.8
debian
3 месяца назад

Vulnerability in Spring Spring Security.SubjectX500PrincipalExtractord ...

CVSS3: 6.8
github
3 месяца назад

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

EPSS

Процентиль: 22%
0.00296
Низкий

6.8 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-297
CWE-295