Описание
Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
A flaw was found in Spring Security, specifically in applications configured for One-Time Token login using JdbcOneTimeTokenService. This vulnerability is due to a Time-of-check Time-of-use (TOCTOU) race condition. A remote attacker with high attack complexity could exploit this flaw to achieve low confidentiality and low integrity impact, potentially leading to unauthorized access or limited information disclosure.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Fix deferred | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Fix deferred | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | spring-security-core | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | spring-security-core | Fix deferred | ||
| Red Hat build of Quarkus | quarkus-spring-security-core-api | Fix deferred | ||
| Red Hat Data Grid 8 | spring-security-core | Fix deferred | ||
| Red Hat Fuse 7 | org.apache.servicemix.bundles.spring-security-core | Fix deferred | ||
| Red Hat Fuse 7 | spring-security-core | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | spring-security-core | Fix deferred |
Показывать по
Дополнительная информация
Статус:
4.8 Medium
CVSS3
Связанные уязвимости
Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
Vulnerability in Spring Spring Security. Applications that explicitly ...
Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured
4.8 Medium
CVSS3