Pivotal Spring Security OAuth CVE-2018-1260 Remote Code Execution Vulnerability
BID:104158
CVE-2018-1260 |Info
Pivotal Spring Security OAuth CVE-2018-1260 Remote Code Execution Vulnerability
| Bugtraq ID: | 104158 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-1260 |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2018 12:00AM |
| Updated: | May 09 2018 12:00AM |
| Credit: | Philippe Arteau from GoSecure |
| Vulnerable: |
Pivotal Spring Security OAuth 2.3.2 Pivotal Spring Security OAuth 2.2.1 Pivotal Spring Security OAuth 2.1.1 Pivotal Spring Security OAuth 2.0.14 Pivotal Spring Security OAuth 2.0.10 Pivotal Spring Security OAuth 2.0.9 Pivotal Spring Security OAuth 2.0.8 Pivotal Spring Security OAuth 2.0.7 Pivotal Spring Security OAuth 2.0.6 Pivotal Spring Security OAuth 2.0.5 Pivotal Spring Security OAuth 2.0.4 Pivotal Spring Security OAuth 2.0.3 Pivotal Spring Security OAuth 2.0.2 Pivotal Spring Security OAuth 2.0.1 Pivotal Spring Security OAuth 2.0 Pivotal Spring Security OAuth 1.0.5 Pivotal Spring Security OAuth 1.0.4 Pivotal Spring Security OAuth 1.0.3 Pivotal Spring Security OAuth 1.0.1 Pivotal Spring Security OAuth 1.0 Pivotal Spring Security OAuth 2.3 Pivotal Spring Security OAuth 2.2 Pivotal Spring Security OAuth 2.1 |
| Not Vulnerable: |
Pivotal Spring Security OAuth 2.3.3 Pivotal Spring Security OAuth 2.2.2 Pivotal Spring Security OAuth 2.1.2 Pivotal Spring Security OAuth 2.0.15 |
Discussion
Pivotal Spring Security OAuth CVE-2018-1260 Remote Code Execution Vulnerability
Pivotal Spring Security OAuth is prone to remote code execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.
The following versions are vulnerable:
Spring Security OAuth 2.3 through 2.3.2
Spring Security OAuth 2.2 through 2.2.1
Spring Security OAuth 2.1 through 2.1.1
Spring Security OAuth 2.0 through 2.0.14
Older unsupported versions
Pivotal Spring Security OAuth is prone to remote code execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.
The following versions are vulnerable:
Spring Security OAuth 2.3 through 2.3.2
Spring Security OAuth 2.2 through 2.2.1
Spring Security OAuth 2.1 through 2.1.1
Spring Security OAuth 2.0 through 2.0.14
Older unsupported versions
Exploit / POC
Pivotal Spring Security OAuth CVE-2018-1260 Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Pivotal Spring Security OAuth CVE-2018-1260 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Pivotal Spring Security OAuth CVE-2018-1260 Remote Code Execution Vulnerability
References:
References:
- Pivotal Homepage (Pivotal)
- CVE-2018-1260: Remote Code Execution with spring-security-oauth2 (Pivotal)