Security features bypass in Spring Boot - CVE-2023-20873

 

Security features bypass in Spring Boot - CVE-2023-20873

Published: April 21, 2023


Vulnerability identifier: #VU75407
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20873
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to security features bypass. A remote attacker can cause security bypass on the target system.


Affected software

Spring Boot
Red Hat Camel for Spring Boot
IBM Observability with Instana
Dell Secure Connect Gateway
Oracle Communications Unified Inventory Management
Oracle Financial Services Model Management and Governance
Oracle Communications Network Analytics Data Director
IBM Process Mining
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM InfoSphere Information Server for Cloud
AMQ Streams
Oracle Utilities Testing Accelerator
Oracle Hospitality Cruise Shipboard Property Management System
Cloud Foundry UAA
Cloud Pak for Security (CP4S)
Dell EMC VxRail Appliance
IBM InfoSphere Information Server
Dell Data Protection Central

How to mitigate CVE-2023-20873

Install updates from vendor's website.

Spring Boot - addressed in versions 2.7.11, 3.0.6
AMQ Streams - update to 2.6.0
Red Hat Camel for Spring Boot - addressed in versions 3.18.3 Patch 2, 3.20.2
Dell Secure Connect Gateway - update to 5.16
Cloud Foundry UAA - update to 76.10.0
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM Process Mining - update to 1.14.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.7
Dell EMC VxRail Appliance - update to 8.0.311
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM InfoSphere Information Server for Cloud - update to 11.7.1.4 Service pack 1
Dell Data Protection Central - update to 19.10.0-4

External References

Related Security Bulletins