Количество 2
Количество 2
CVE-2018-1256
Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.
GHSA-q4q2-93pw-qwgf
Issuer validation regression in Spring Cloud SSO Connector
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-1256 Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan. | CVSS3: 8.1 | 0% Низкий | почти 8 лет назад | |
GHSA-q4q2-93pw-qwgf Issuer validation regression in Spring Cloud SSO Connector | CVSS3: 8.1 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу