Permissions, Privileges, and Access Controls in Spring Security - CVE-2022-31690

 

Permissions, Privileges, and Access Controls in Spring Security - CVE-2022-31690

Published: November 1, 2022


Vulnerability identifier: #VU68865
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31690
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions in spring-security-oauth2-client. A remote user can modify a request initiated by the Client to the Authorization Server and gain elevated privileges on the system.


Affected software

Spring Security
Migration Toolkit for Runtimes
IBM Process Mining
Red Hat Migration Toolkit for Applications
IBM Sterling Partner Engagement Manager
IBM Data Risk Manager
Multicluster Engine for Kubernetes
Red Hat OpenShift Container Platform
toolbox (Red Hat package)
cri-o (Red Hat package)
haproxy (Red Hat package)
jenkins (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
jenkins-2-plugins (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
Cloud Pak for Network Automation
Storage Protect Plus Server

How to mitigate CVE-2022-31690

Install updates from vendor's website.

Spring Security - addressed in versions 5.6.9, 5.7.5
Migration Toolkit for Runtimes - update to 1.0.2
IBM Process Mining - update to 1.14.0.0
IBM Data Risk Manager - update to 2.0.6.15
Multicluster Engine for Kubernetes - update to 2.2.4
Red Hat OpenShift Container Platform - update to 4.10.56
Red Hat Migration Toolkit for Applications - update to 6.1.0
toolbox (Red Hat package) - update to 0.0.9-1.rhaos4.10.el8
cri-o (Red Hat package) - addressed in versions 1.23.5-8.rhaos4.10.gitcc8441d.el7, 1.23.5-8.rhaos4.10.gitcc8441d.el8
haproxy (Red Hat package) - update to 2.2.19-4.el8
Cloud Pak for Network Automation - update to 2.6.0
jenkins (Red Hat package) - update to 2.387.1.1680701869-1.el8
openshift (Red Hat package) - addressed in versions 4.10.0-202303221742.p0.g16bcd69.assembly.stream.el7, 4.10.0-202303221742.p0.g16bcd69.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.10.0-202304032041.p0.g3a7500d.assembly.stream.el7, 4.10.0-202304032041.p0.g3a7500d.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.10.1680703106-1.el8
kernel (Red Hat package) - update to 4.18.0-305.85.1.el8_4
kernel-rt (Red Hat package) - update to 4.18.0-305.85.1.rt7.157.el8_4
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.7, 6.2.0.5, 6.2.1.2
Storage Protect Plus Server - update to 10.1.16.1

External References

Related Security Bulletins