Spring Security 'RunAsManager' Local Privilege Escalation Vulnerability
BID:49538
Info
Spring Security 'RunAsManager' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 49538 |
| Class: | Race Condition Error |
| CVE: |
CVE-2011-2731 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 09 2011 12:00AM |
| Updated: | Mar 19 2015 09:36AM |
| Credit: | Rob Winch |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Spring Security 'RunAsManager' Local Privilege Escalation Vulnerability
Spring Security is prone to a local privilege-escalation vulnerability.
Local attackers may exploit this issue to gain elevated privileges and perform unauthorized actions.
The following versions are vulnerable:
Spring Security 2.0.0 through 2.0.6
Spring Security 3.0.0 through 3.0.5
Spring Security is prone to a local privilege-escalation vulnerability.
Local attackers may exploit this issue to gain elevated privileges and perform unauthorized actions.
The following versions are vulnerable:
Spring Security 2.0.0 through 2.0.6
Spring Security 3.0.0 through 3.0.5
Exploit / POC
Spring Security 'RunAsManager' Local Privilege Escalation Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Spring Security 'RunAsManager' Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Spring Security 'RunAsManager' Local Privilege Escalation Vulnerability
References:
References:
- SpringSource Homepage (SpringSource)
- CVE-2011-2731: Spring Security privilege escalation when using RunAsManager (s2-security
) - CVE-2011-2731: Spring Security privilege escalation when using RunAsManager (SpringSource)