Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-34042

Опубликовано: 05 фев. 2024
Источник: redhat
CVSS3: 5.5

Описание

The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access to the file system. While there are no known exploits, this is an example of “CWE-732: Incorrect Permission Assignment for Critical Resource” and could result in an exploit. Users should update to the latest version of Spring Security to mitigate any future exploits found around this issue.

A flaw was found in the Spring-security-config jar file. The spring-security.xsd file inside the spring-security-config jar is world-writable, which means that if it were extracted, it could be written by anyone with access to the file system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2spring-security-configNot affected
Red Hat build of Apache Camel for Spring Boot 3spring-security-configOut of support scope
Red Hat build of Apache Camel for Spring Boot 4spring-security-configNot affected
Red Hat Build of Keycloakspring-security-configNot affected
Red Hat Data Grid 8spring-security-configNot affected
Red Hat Decision Manager 7spring-security-configWill not fix
Red Hat Fuse 7spring-security-configAffected
Red Hat Integration Camel K 1spring-security-configWill not fix
Red Hat JBoss Data Grid 7spring-security-configNot affected
Red Hat JBoss Enterprise Application Platform 6org.keycloak-keycloak-parentOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=2262911spring-security-config: Incorrect Permission Assignment for spring-security.xsd

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.1
nvd
около 2 лет назад

The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access to the file system. While there are no known exploits, this is an example of “CWE-732: Incorrect Permission Assignment for Critical Resource” and could result in an exploit. Users should update to the latest version of Spring Security to mitigate any future exploits found around this issue.

CVSS3: 5.5
github
около 2 лет назад

Spring Security's spring-security.xsd file is world writable

5.5 Medium

CVSS3