CVE-2023-20862

MEDIUM

Spring Security <5.7.8-<5.8.3-<6.0.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the HttpSessionSecurityContextRepository. This vulnerability can keep users authenticated even after they performed logout. Users of affected versions should apply the following mitigation. 5.7.x users should upgrade to 5.7.8. 5.8.x users should upgrade to 5.8.3. 6.0.x users should upgrade to 6.0.3.

Scores

CVSS v3 6.3
EPSS 0.0040
EPSS Percentile 60.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-459
Status published
Products (3)
netapp/active_iq_unified_manager (3 CPE variants)
org.springframework.security/spring-security-core 5.7.0 - 5.7.8Maven
vmware/spring_security 5.7.0 - 5.7.8
Published Apr 19, 2023
Tracked Since Feb 18, 2026