Security features bypass in Spring Security - CVE-2023-20862

 

Security features bypass in Spring Security - CVE-2023-20862

Published: April 21, 2023


Vulnerability identifier: #VU75408
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20862
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the logout support does not properly clean the security context if using serialized versions. A remote attacker can save an empty security context to the HttpSessionSecurityContextRepository and keep users authenticated even after they performed logout.


Affected software

Spring Security
IBM Data Risk Manager
IBM Db2 Web Query for i
Oracle Utilities Testing Accelerator
Cloudera Data Platform Private Cloud Base for IBM
OpenShift Developer Tools and Services
Dell Policy Manager for Secure Connect Gateway (SCG)
IBM i Modernization Engine for Lifecycle Integration
Oracle Communications Unified Inventory Management
Oracle Financial Services Model Management and Governance
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications Cloud Native Core Network Exposure Function
IBM Process Mining
IBM Maximo Application Suite
IBM Common Licensing
MySQL Enterprise Monitor
IBM InfoSphere Information Server
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Console
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Cloud Foundry UAA
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
Operational Decision Manager

How to mitigate CVE-2023-20862

Install updates from vendor's website.

Spring Security - addressed in versions 5.7.8, 5.8.3, 6.0.3
IBM Data Risk Manager - update to 2.0.6.17
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.16.00.14
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.9.3 HF2
Cloud Foundry UAA - update to 76.10.0
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.2
IBM Process Mining - update to 1.14.1
jenkins (Red Hat package) - update to 2.426.3.1706515686-3.el8
jenkins-2-plugins (Red Hat package) - update to 4.12.1706515741-1.el8
IBM Maximo Application Suite - addressed in versions 8.9.6, 8.10.4
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 36, 8.11.0.1 Interim fix 17, 8.11.0.1 Interim fix 18, 8.11.1 Interim fix 7
IBM Common Licensing - update to 9.0.0.1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

External References

Related Security Bulletins