CVE-2018-15801
published 2018-12-19CVE-2018-15801: Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same…
PriorityP340high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.65%
47.3th percentile
Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious issuer URL that may be granted for the honest issuer.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring_by_pivotal | spring_security | >= 5.1.x < 5.1.2 | 5.1.2 |
| vmware | spring_framework | >= 5.1.0 < 5.1.2 | 5.1.2 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.03.3LOWCVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Spring Security vulnerable to Authorization Bypass
osv·2018-12-20
CVE-2018-15801 [HIGH] Spring Security vulnerable to Authorization Bypass
Spring Security vulnerable to Authorization Bypass
Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious issuer URL that may be granted for the honest issuer.
GHSA
Spring Security vulnerable to Authorization Bypass
ghsa·2018-12-20
CVE-2018-15801 [HIGH] CWE-345 Spring Security vulnerable to Authorization Bypass
Spring Security vulnerable to Authorization Bypass
Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious issuer URL that may be granted for the honest issuer.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-12-19
Published