Security features bypass in Spring Security - CVE-2023-34034

 

Security features bypass in Spring Security - CVE-2023-34034

Published: September 19, 2023


Vulnerability identifier: #VU80880
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34034
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to the usage of "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux. A remote unauthenticated attacker can trigger the vulnerability to bypass security restrictions.


Affected software

Spring Security
IBM Db2 Web Query for i
Oracle WebCenter Sites
Oracle Banking Origination
Oracle Banking Corporate Lending Process Management
Oracle Banking Liquidity Management
IBM Data Risk Manager
Cloudera Data Platform Private Cloud Base for IBM
Oracle Communications Unified Inventory Management
IBM Automation Decision Services
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
IBM Cloud Pak for Business Automation
Communications Service Catalog and Design
Fuse
MySQL Enterprise Monitor
Oracle Banking Digital Experience
ObjectScale
Cloud Pak for Network Automation
Dell Data Protection Central
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Network Slice Selection Function
Operational Decision Manager

How to mitigate CVE-2023-34034

Install updates from vendor's website.

Spring Security - addressed in versions 5.6.12, 5.7.10, 5.8.5, 6.0.5, 6.1.2
Fuse - update to 7.12.1
IBM Automation Decision Services - update to 23.0.1 IF005
ObjectScale - update to 1.4.0
IBM Data Risk Manager - update to 2.0.6.20
Cloud Pak for Network Automation - update to 2.6.2
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.9.3 HF2
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 41, 8.11.0.1 Interim fix 21, 8.11.1 Interim fix 10, 8.12.0 Interim fix 2
Dell Data Protection Central - update to 19.10.0-4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.27, 23.0.1.5

External References

Related Security Bulletins