Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-22747

Опубликовано: 22 апр. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.

A flaw was found in Spring Security. This vulnerability allows a remote attacker to impersonate another user. The SubjectX500PrincipalExtractor component incorrectly handles certain malformed X.509 certificate Common Name (CN) values, which can lead to the system reading an incorrect username. By presenting a carefully crafted certificate, an attacker can exploit this to gain unauthorized access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsNot affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Not affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Not affected
Red Hat build of Apache Camel for Spring Boot 4spring-security-coreNot affected
Red Hat build of Apache Camel - HawtIO 4spring-security-coreNot affected
Red Hat build of Quarkusquarkus-spring-security-core-apiNot affected
Red Hat Data Grid 8spring-security-coreNot affected
Red Hat Fuse 7org.apache.servicemix.bundles.spring-security-coreNot affected
Red Hat Fuse 7spring-security-coreNot affected
Red Hat JBoss Enterprise Application Platform 7spring-security-coreNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2460487Spring Security: Spring Security: User impersonation via malformed X.509 certificate Common Name (CN) values

EPSS

Процентиль: 22%
0.00296
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
3 месяца назад

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.

CVSS3: 6.8
nvd
3 месяца назад

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.

CVSS3: 6.8
debian
3 месяца назад

Vulnerability in Spring Spring Security.SubjectX500PrincipalExtractord ...

CVSS3: 6.8
github
3 месяца назад

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

EPSS

Процентиль: 22%
0.00296
Низкий

8.1 High

CVSS3