Improper access control in Spring Security - CVE-2024-22257

 

Improper access control in Spring Security - CVE-2024-22257

Published: March 19, 2024


Vulnerability identifier: #VU87607
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22257
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions when the "AuthenticatedVoter#vote" passing a "null" Authentication parameter. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application.


Affected software

Spring Security
Confluence Server
Confluence Data Center
Crucible Server
Crucible Data Center
Crowd Data Center
Jira Service Management Data Center
Jira Service Management Server
Oracle Communications Unified Inventory Management
Bitbucket Data Center
Bamboo Server
Jira Software Data Center
Oracle SD-WAN Edge
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
Unified OSS Console Assurance Monitoring (UOCAM)
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
webMethods Managed File Transfer
Cloud Pak for Network Automation
Storage Resource Manager
Dell Policy Manager for Secure Connect Gateway (SCG)
IBM Sterling Connect:Direct for Microsoft Windows
Maximo Application Suite - Monitor Component
Dell Data Protection Central
Crowd Server
MySQL Enterprise Monitor
Bitbucket Server
Jira Software Server
Oracle Insurance Policy Administration
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Console
QRadar Suite
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC VxRail Appliance

How to mitigate CVE-2024-22257

Install updates from vendor's website.

Spring Security - addressed in versions 5.7.12, 5.8.11, 6.1.8, 6.2.3
Confluence Server - addressed in versions 7.19.22, 8.5.9, 8.9.1
Confluence Data Center - addressed in versions 7.19.22, 8.5.9, 8.9.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
Crucible Server - update to 4.9.11
Crucible Data Center - update to 4.9.11
Crowd Data Center - addressed in versions 5.0.11, 5.1.9, 5.2.4
Crowd Server - addressed in versions 5.0.11, 5.1.9, 5.2.4
Jira Service Management Data Center - addressed in versions 5.4.20, 5.12.7, 5.15.2
Jira Service Management Server - addressed in versions 5.4.20, 5.12.7, 5.15.2
Bitbucket Data Center - addressed in versions 8.9.12, 8.19.1
Bitbucket Server - addressed in versions 8.9.12, 8.19.1
Bamboo Server - addressed in versions 9.2.13, 9.5.3, 9.6.1
Jira Software Data Center - addressed in versions 9.4.20, 9.12.7, 9.15.2
Jira Software Server - addressed in versions 9.4.20, 9.12.7, 9.15.2
QRadar Suite - update to 1.10.22.0
Cloud Pak for Network Automation - update to 2.7.5
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.4
Storage Resource Manager - update to 5.0.2.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.2.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
IBM Sterling Connect:Direct for Microsoft Windows - update to 6.3.0.3 iFix002
Dell EMC VxRail Appliance - update to 8.0.311
Maximo Application Suite - Monitor Component - addressed in versions 8.10.9, 8.11.6
Dell Data Protection Central - update to 19.11.0-2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.32, 23.0.2.4
IBM Automation Decision Services - update to 23.0.2.0.4

External References

Related Security Bulletins