Описание
In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to
5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8,
versions 6.2.x prior to 6.2.3, an application is possible vulnerable to
broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.
A broken access control flaw was found in Spring Security. Applications may be vulnerable when directly using the AuthenticatedVoter#vote passing a NULL authentication parameter.
Отчет
The AuthenticatedVoter class was deprecated since Spring Security 5.8 is used in favor of the AuthorizationManager class, which is not vulnerable to this issue.
Меры по смягчению последствий
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| A-MQ Clients 2 | spring-security | Not affected | ||
| OpenShift Developer Tools and Services | jenkins | Will not fix | ||
| Red Hat build of Apache Camel for Spring Boot 3 | spring-security | Affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | spring-security | Affected | ||
| Red Hat build of Apache Camel - HawtIO 4 | spring-security | Will not fix | ||
| Red Hat Build of Keycloak | spring-security | Not affected | ||
| Red Hat Data Grid 8 | spring-security | Not affected | ||
| Red Hat Fuse 7 | spring-security | Affected | ||
| Red Hat Integration Camel K 1 | spring-security | Not affected | ||
| Red Hat JBoss Data Grid 7 | spring-security | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.
In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5. ...
Erroneous authentication pass in Spring Security
Уязвимость класса AuthenticatedVoter Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
9.8 Critical
CVSS3