Описание
Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
A flaw was found in Spring Security. When an application is configured to decode JSON Web Tokens (JWTs) using NimbusJwtDecoder or NimbusReactiveJwtDecoder, it may not properly validate these tokens if an OAuth2TokenValidator<Jwt> is not explicitly configured. This oversight could allow an attacker with low privileges to bypass security checks, potentially leading to unauthorized actions or data manipulation within the application.
Меры по смягчению последствий
To mitigate this issue, applications using Spring Security's NimbusJwtDecoder or NimbusReactiveJwtDecoder must explicitly configure an OAuth2TokenValidator<Jwt>. This ensures proper validation of JSON Web Tokens, preventing unauthorized access or data manipulation. Consult Spring Security documentation for correct implementation of OAuth2TokenValidator<Jwt> within your application's security configuration. A restart or reload of the affected application may be required for the changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Fix deferred | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Fix deferred | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | spring-security-core | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | spring-security-core | Fix deferred | ||
| Red Hat build of Quarkus | quarkus-spring-security-core-api | Fix deferred | ||
| Red Hat Data Grid 8 | spring-security-core | Fix deferred | ||
| Red Hat Fuse 7 | org.apache.servicemix.bundles.spring-security-core | Fix deferred | ||
| Red Hat Fuse 7 | spring-security-core | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | spring-security-core | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
Vulnerability in Spring Spring Security. When an application configure ...
Spring Security has Potential Security Misconfiguration when Using withIssuerLocation
EPSS
5.3 Medium
CVSS3