Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-22748

Опубликовано: 22 апр. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

A flaw was found in Spring Security. When an application is configured to decode JSON Web Tokens (JWTs) using NimbusJwtDecoder or NimbusReactiveJwtDecoder, it may not properly validate these tokens if an OAuth2TokenValidator<Jwt> is not explicitly configured. This oversight could allow an attacker with low privileges to bypass security checks, potentially leading to unauthorized actions or data manipulation within the application.

Меры по смягчению последствий

To mitigate this issue, applications using Spring Security's NimbusJwtDecoder or NimbusReactiveJwtDecoder must explicitly configure an OAuth2TokenValidator<Jwt>. This ensures proper validation of JSON Web Tokens, preventing unauthorized access or data manipulation. Consult Spring Security documentation for correct implementation of OAuth2TokenValidator<Jwt> within your application's security configuration. A restart or reload of the affected application may be required for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsFix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Fix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Fix deferred
Red Hat build of Apache Camel for Spring Boot 4spring-security-coreFix deferred
Red Hat build of Apache Camel - HawtIO 4spring-security-coreFix deferred
Red Hat build of Quarkusquarkus-spring-security-core-apiFix deferred
Red Hat Data Grid 8spring-security-coreFix deferred
Red Hat Fuse 7org.apache.servicemix.bundles.spring-security-coreFix deferred
Red Hat Fuse 7spring-security-coreFix deferred
Red Hat JBoss Enterprise Application Platform 7spring-security-coreFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2460488Spring Security: Spring Security: Integrity impact due to improper JSON Web Token (JWT) validation

EPSS

Процентиль: 11%
0.00203
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

CVSS3: 5.3
nvd
4 месяца назад

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

CVSS3: 5.3
debian
4 месяца назад

Vulnerability in Spring Spring Security. When an application configure ...

CVSS3: 5.3
github
4 месяца назад

Spring Security has Potential Security Misconfiguration when Using withIssuerLocation

EPSS

Процентиль: 11%
0.00203
Низкий

5.3 Medium

CVSS3