PT-2026-48333 · Vmware · Spring Security
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Security versions 5.7.0 through 5.7.24
Spring Security versions 5.8.0 through 5.8.26
Spring Security versions 6.3.0 through 6.3.17
Spring Security versions 6.4.0 through 6.4.17
Spring Security versions 6.5.0 through 6.5.10
Description
The
SubjectDnX509PrincipalExtractor() function does not correctly handle certain malformed X.509 certificate Common Name (CN) values. This flaw can result in the system reading an incorrect value for the username, allowing an attacker using a carefully crafted certificate to impersonate another user.Recommendations
Update versions 5.7.0 through 5.7.24 to a version later than 5.7.24.
Update versions 5.8.0 through 5.8.26 to a version later than 5.8.26.
Update versions 6.3.0 through 6.3.17 to a version later than 6.3.17.
Update versions 6.4.0 through 6.4.17 to a version later than 6.4.17.
Update versions 6.5.0 through 6.5.10 to a version later than 6.5.10.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Security