Spring by Pivotal Vulnerabilities and Affected Products
Vulnerabilities associated with Spring Security.
Products
Clear product- Spring Framework6 vulnerabilities
- Spring Batch Admin2 vulnerabilities
- Spring Security1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-15801HIGH | Authorization Bypass During JWT Issuer Validation with spring-securitySpring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious issuer URL that may be granted for the honest issuer. CWE-345Dec 19, 2018 | CVSS7.4v3.1 | EPSS0.653% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |