Описание
The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.
A timing weakness has been discovered in the Spring Framework security core package. The fix applied for CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Fix deferred | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | spring-security-core | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | spring-security-core | Fix deferred | ||
| Red Hat Data Grid 8 | spring-security-core | Fix deferred | ||
| Red Hat Fuse 7 | spring-security-core | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | spring-security-core | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 8 | spring-security-core | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-security-core | Fix deferred | ||
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.
The fix applied in CVE-2025-22228 inadvertently broke the timing attac ...
Spring Security has a broken timing attack mitigation implemented in DaoAuthenticationProvide
Уязвимость Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, связанная с нарушением механизма защиты данных, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
EPSS
5.3 Medium
CVSS3