Input validation error in Spring Framework - CVE-2023-20860

 

Input validation error in Spring Framework - CVE-2023-20860

Published: April 27, 2023


Vulnerability identifier: #VU75561
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20860
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an input validation error caused by using the wildcard ("**") as a pattern in Spring Security configuration with the mvcRequestMatcher, which creates a mismatch in pattern matching between Spring Security and Spring MVC. A remote attacker can bypass certain security restrictions.


Affected software

Spring Framework
IBM Observability with Instana
IBM Process Mining
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Sterling B2B Integrator
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Connect:Direct for UNIX
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
Red Hat Openshift Application Runtimes
Red Hat OpenShift Container Platform
ObjectScale
Dell Policy Manager for Secure Connect Gateway (SCG)
IBM Business Automation Manager Open Editions
IBM i Modernization Engine for Lifecycle Integration
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
IBM Sterling Connect:Direct for Microsoft Windows
IBM Data Risk Manager
IBM Db2 Web Query for i
IBM Tivoli Application Dependency Discovery Manager
Red Hat Virtualization Manager
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
AMQ Broker
Oracle WebLogic Server
Fuse
IBM InfoSphere Information Server
Identity Manager
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
cri-o (Red Hat package)
jenkins (Red Hat package)
ovirt-dependencies (Red Hat package)
ovirt-engine (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
jenkins-2-plugins (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
vdsm (Red Hat package)
Red Hat Camel for Spring Boot
Operational Decision Manager

How to mitigate CVE-2023-20860

Install updates from vendor's website.

Spring Framework - addressed in versions 5.3.26, 6.0.7
ObjectScale - update to 1.3.0
IBM Data Risk Manager - update to 2.0.6.17
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
Red Hat OpenShift Container Platform - update to 4.10.62
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.16.00.14
IBM Sterling B2B Integrator - addressed in versions 6.0.3.9, 6.1.0.8, 6.1.1.4, 6.1.2.3, 6.2.0.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.4
AMQ Broker - update to 7.10.3
IBM Business Automation Manager Open Editions - update to 8.0.4
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.2
Cloud Pak for Security (CP4S) - update to 1.10.12.0
cri-o (Red Hat package) - addressed in versions 1.23.5-16.rhaos4.10.gitbb2cc9a.el7, 1.23.5-16.rhaos4.10.gitbb2cc9a.el8
Cloud Pak for Network Automation - update to 2.7
jenkins (Red Hat package) - addressed in versions 2.401.1.1685677065-1.el8, 2.401.1.1686649641-3.el8, 2.401.1.1686680404-3.el8, 2.401.1.1686831596-3.el8
IBM Cloud Pak for Watson AIOps - update to 3.7.2
Red Hat Camel for Spring Boot - update to 3.20.1
ovirt-dependencies (Red Hat package) - update to 4.5.3-1.el8ev
ovirt-engine (Red Hat package) - update to 4.5.3.8-2.el8ev
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.7
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.7
openshift-clients (Red Hat package) - addressed in versions 4.10.0-202306081029.p0.g3a7500d.assembly.stream.el7, 4.10.0-202306081029.p0.g3a7500d.assembly.stream.el8
openshift (Red Hat package) - addressed in versions 4.10.0-202306081029.p0.g16bcd69.assembly.stream.el7, 4.10.0-202306081029.p0.g16bcd69.assembly.stream.el8
openshift-ansible (Red Hat package) - addressed in versions 4.10.0-202306081029.p0.g72c7be6.assembly.stream.el7, 4.10.0-202306081029.p0.g72c7be6.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 4.10.1685679861-1.el8, 4.11.1686831822-1.el8, 4.12.1686649756-1.el8, 4.13.1686680473-1.el8
kernel (Red Hat package) - update to 4.18.0-305.93.1.el8_4
kernel-rt (Red Hat package) - update to 4.18.0-305.93.1.rt7.168.el8_4
vdsm (Red Hat package) - update to 4.50.3.8-1.el8ev
IBM Sterling Connect:Direct for Microsoft Windows - update to 6.2.0.4.33
IBM Sterling Connect:Direct for UNIX - update to 6.2.0.6.13
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
Fuse - update to 7.12.0
IBM Maximo Application Suite - addressed in versions 8.9.6, 8.10.4
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 34, 8.11.0.1 Interim fix 17, 8.11.1 Interim fix 5
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.21, 22.0.2.5

External References

Related Security Bulletins