V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-22112
DEB
High

Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail t…

CVSS
8.8
High
EPSS
0.03
p86
Published
2021-01-01
Updated
2021-01-01
Description

Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to run with elevated privileges in a small portion of the application, the bug can be leveraged to extend those privileges to the rest of the application.

Tags · CWE
CWE-281
Affected products
Communications_element_manager 8.2.0–8.2.4.0Communications_interactive_session_recorderCommunications_unified_inventory_managementHospitality_cruise_shipboard_property_management_systemInsurance_policy_administrationMysql_enterprise_monitor ≤ 8.0.25
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.032 · p86
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
jenkinsTracked
communications_element_manager*Tracked
communications_interactive_session_recorder*Tracked
communications_unified_inventory_management*Tracked
hospitality_cruise_shipboard_property_management_system*Tracked
insurance_policy_administration*Tracked
mysql_enterprise_monitor*Tracked
spring_security*Tracked
Source databases
DEB
CVE