Permissions, Privileges, and Access Controls in Spring Security - CVE-2022-31690
Published: November 1, 2022
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in spring-security-oauth2-client. A remote user can modify a request initiated by the Client to the Authorization Server and gain elevated privileges on the system.
Affected software
Migration Toolkit for Runtimes
IBM Process Mining
Red Hat Migration Toolkit for Applications
IBM Sterling Partner Engagement Manager
IBM Data Risk Manager
Multicluster Engine for Kubernetes
Red Hat OpenShift Container Platform
toolbox (Red Hat package)
cri-o (Red Hat package)
haproxy (Red Hat package)
jenkins (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
jenkins-2-plugins (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
Cloud Pak for Network Automation
Storage Protect Plus Server
How to mitigate CVE-2022-31690
Migration Toolkit for Runtimes - update to 1.0.2
IBM Process Mining - update to 1.14.0.0
IBM Data Risk Manager - update to 2.0.6.15
Multicluster Engine for Kubernetes - update to 2.2.4
Red Hat OpenShift Container Platform - update to 4.10.56
Red Hat Migration Toolkit for Applications - update to 6.1.0
toolbox (Red Hat package) - update to 0.0.9-1.rhaos4.10.el8
cri-o (Red Hat package) - addressed in versions 1.23.5-8.rhaos4.10.gitcc8441d.el7, 1.23.5-8.rhaos4.10.gitcc8441d.el8
haproxy (Red Hat package) - update to 2.2.19-4.el8
Cloud Pak for Network Automation - update to 2.6.0
jenkins (Red Hat package) - update to 2.387.1.1680701869-1.el8
openshift (Red Hat package) - addressed in versions 4.10.0-202303221742.p0.g16bcd69.assembly.stream.el7, 4.10.0-202303221742.p0.g16bcd69.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.10.0-202304032041.p0.g3a7500d.assembly.stream.el7, 4.10.0-202304032041.p0.g3a7500d.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.10.1680703106-1.el8
kernel (Red Hat package) - update to 4.18.0-305.85.1.el8_4
kernel-rt (Red Hat package) - update to 4.18.0-305.85.1.rt7.157.el8_4
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
Storage Protect Plus Server - update to 10.1.16.1
External References
Related Security Bulletins
- Multiple vulnerabilities in VMware Spring Security
- Multiple vulnerabilities in IBM Data Risk Manager
- Permissions, privileges, and access controls in IBM Sterling Partner Engagement Manager
- Multiple vulnerabilities in Migration Toolkit for Runtimes
- Multiple vulnerabilities in Migration Toolkit for Runtimes
- Multiple vulnerabilities in OpenShift Container Platform 4.10
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.10
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Permissions, privileges, and access controls in IBM Process Mining
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.2
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM Storage Protect Plus Server