CVE-2014-3527
published 2017-05-25CVE-2014-3527: When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a…
PriorityP355critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.81%
76.0th percentile
When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request. This means if there are access control restrictions on which CAS services can authenticate to one another, those restrictions can be bypassed. If users are not using CAS Proxy tickets and not basing access control decisions based upon the CAS Service, then there is no impact to users.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| pivotal | spring_security | — | — |
| vmware | spring_security | — | — |
| vmware | spring_security | — | — |
| vmware | spring_security | — | — |
| vmware | spring_security | — | — |
| vmware | spring_security | — | — |
| vmware | spring_security | — | — |
| vmware | spring_security | — | — |
| vmware | spring_security | — | — |
| vmware | spring_security | — | — |
| vmware | spring_security | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Authorization Bypass in Spring Security
ghsa·2020-09-15
CVE-2014-3527 [CRITICAL] CWE-287 Authorization Bypass in Spring Security
Authorization Bypass in Spring Security
When using Spring Security's CAS Proxy ticket authentication a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request.
This means if there are access control restrictions on which CAS services can authenticate to one another, those restrictions can be bypassed.
If users are not using CAS Proxy tickets and not basing access control decisions based upon the CAS Service, then there is no impact to users.
## Mitigation
Users of affected versions should apply the following mitigation:
- Users of 3.2x should upg
OSV
Authorization Bypass in Spring Security
osv·2020-09-15
CVE-2014-3527 [CRITICAL] Authorization Bypass in Spring Security
Authorization Bypass in Spring Security
When using Spring Security's CAS Proxy ticket authentication a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request.
This means if there are access control restrictions on which CAS services can authenticate to one another, those restrictions can be bypassed.
If users are not using CAS Proxy tickets and not basing access control decisions based upon the CAS Service, then there is no impact to users.
## Mitigation
Users of affected versions should apply the following mitigation:
- Users of 3.2x should upg
Red Hat
CAS: Access control bypass via untrusted infomation usage in proxy ticket authentication
vendor_redhat·2014-07-24·CVSS 9.8
CVE-2014-3527 [CRITICAL] CWE-348 CAS: Access control bypass via untrusted infomation usage in proxy ticket authentication
CAS: Access control bypass via untrusted infomation usage in proxy ticket authentication
When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request. This means if there are access control restrictions on which CAS services can authenticate to one another, those restrictions can be bypassed. If users are not using CAS Proxy tickets and not basing access control decisions based upon the CAS Service, then there is no impact to users.
When using Spring Security's CAS Proxy
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3527 springframework-security: Spring Security CAS: Access control bypass via untrusted infomation usage in proxy ticket authentication [fedora-all]
bugzilla·2014-08-19·CVSS 9.8
CVE-2014-3527 [CRITICAL] CVE-2014-3527 springframework-security: Spring Security CAS: Access control bypass via untrusted infomation usage in proxy ticket authentication [fedora-all]
CVE-2014-3527 springframework-security: Spring Security CAS: Access control bypass via untrusted infomation usage in proxy ticket authentication [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bugzilla
CVE-2014-3527 Spring Security CAS: Access control bypass via untrusted infomation usage in proxy ticket authentication
bugzilla·2014-08-19·CVSS 9.8
CVE-2014-3527 [CRITICAL] CVE-2014-3527 Spring Security CAS: Access control bypass via untrusted infomation usage in proxy ticket authentication
CVE-2014-3527 Spring Security CAS: Access control bypass via untrusted infomation usage in proxy ticket authentication
When using Spring Security's CAS Proxy ticket authentication a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request. A remote attacker could use this flaw to bypass any access control restrictions on which CAS services can authenticate to one another.
References:
http://www.gopivotal.com/security/cve-2014-3527
https://spring.io/blog/2014/08/15/cve-2014-3527-fixed-in-spring-security-3-2-5-and-3-1-7
Upstream Issue:
https://jira
2017-05-25
Published