Improper Authentication in Spring Authorization Server - CVE-2024-22258
Published: March 20, 2024
Vulnerability identifier: #VU87654
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22258
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to PKCE downgrade when a Confidential Client uses PKCE for the Authorization Code Grant. A remote attacker can bypass authentication process and gain unauthorized access to the application.
Affected software
Spring Authorization Server
Cloud Pak for Network Automation
Cloud Pak for Network Automation
How to mitigate CVE-2024-22258
Install updates from vendor's website.
Spring Authorization Server - addressed in versions 1.0.6, 1.1.6, 1.2.3
Cloud Pak for Network Automation - update to 2.7.5
Cloud Pak for Network Automation - update to 2.7.5