QID 996929
Date Published: 2024-01-30
QID 996929: Java (Maven) Security Update for io.pivotal.spring.cloud:spring-cloud-sso-connector (GHSA-q4q2-93pw-qwgf)
Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-q4q2-93pw-qwgf for updates and patch information.
Vendor References
- GHSA-q4q2-93pw-qwgf -
github.com/advisories/GHSA-q4q2-93pw-qwgf
CVEs related to QID 996929
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-q4q2-93pw-qwgf | io.pivotal.spring.cloud:spring-cloud-sso-connector |
|