Permissions, Privileges, and Access Controls in Spring Security - CVE-2021-22112

 

Permissions, Privileges, and Access Controls in Spring Security - CVE-2021-22112

Published: February 22, 2021


Vulnerability identifier: #VU50820
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22112
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to the affected software can fail to save the SecurityContext if it is changed more than once in a single request. A remote authenticated attacker can gain elevated privileges on the target system.


Affected software

Spring Security
Jenkins
Oracle Communications Interactive Session Recorder
Oracle Communications Unified Inventory Management
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
MySQL Enterprise Monitor
Oracle Insurance Policy Administration
Oracle Hospitality Cruise Shipboard Property Management System
CloudLink
IBM Cognos Controller

How to mitigate CVE-2021-22112

Install updates from vendor's website.

Spring Security - addressed in versions 5.2.9, 5.3.8, 5.4.4
Jenkins - update to 2.280
MySQL Enterprise Monitor - update to 8.0.27
CloudLink - update to 8.0-3.10.5.1
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.30, 23.0.2.2
IBM Automation Decision Services - update to 23.0.2.0.2

External References

Related Security Bulletins