CVE-2023-20862
published 2023-04-19CVE-2023-20862: In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean…
PriorityP338medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.65%
47.3th percentile
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the HttpSessionSecurityContextRepository. This vulnerability can keep users authenticated even after they performed logout. Users of affected versions should apply the following mitigation. 5.7.x users should upgrade to 5.7.8. 5.8.x users should upgrade to 5.8.3. 6.0.x users should upgrade to 6.0.3.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | spring_security | — | — |
| vmware | spring_security | >= 5.7.0 < 5.7.8 | 5.7.8 |
| vmware | spring_security | >= 5.8.0 < 5.8.3 | 5.8.3 |
| vmware | spring_security | >= 6.0.0 < 6.0.3 | 6.0.3 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
vendor_oracle9.8MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Installer (Spring Security) — CVE-2023-20862
vendor_oracle·2023-10-15·CVSS 6.3
CVE-2023-20862 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Installer (Spring Security) — CVE-2023-20862
Oracle Oracle Financial Services Applications Risk Matrix: Installer (Spring Security) vulnerability
CVE: CVE-2023-20862
CVSS: 6.3
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Spring Security) — CVE-2023-20862
vendor_oracle·2023-07-15·CVSS 9.8
CVE-2023-20862 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Security (Spring Security) — CVE-2023-20862
Oracle Oracle Communications Applications Risk Matrix: Security (Spring Security) vulnerability
CVE: CVE-2023-20862
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Red Hat
spring-security: Empty SecurityContext Is Not Properly Saved Upon Logout
vendor_redhat·2023-04-19·CVSS 6.3
CVE-2023-20862 [MEDIUM] CWE-459 spring-security: Empty SecurityContext Is Not Properly Saved Upon Logout
spring-security: Empty SecurityContext Is Not Properly Saved Upon Logout
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the HttpSessionSecurityContextRepository. This vulnerability can keep users authenticated even after they performed logout. Users of affected versions should apply the following mitigation. 5.7.x users should upgrade to 5.7.8. 5.8.x users should upgrade to 5.8.3. 6.0.x users should upgrade to 6.0.3.
A flaw was found in Spring Security. In affected versions of Spring Security, the logout support does not properly clean the securit
GHSA
Spring Security logout not clearing security context
ghsa·2023-04-19
CVE-2023-20862 [MEDIUM] CWE-459 Spring Security logout not clearing security context
Spring Security logout not clearing security context
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the HttpSessionSecurityContextRepository. This vulnerability can keep users authenticated even after they performed logout. Users of affected versions should apply the following mitigation. 5.7.x users should upgrade to 5.7.8. 5.8.x users should upgrade to 5.8.3. 6.0.x users should upgrade to 6.0.3.
OSV
Spring Security logout not clearing security context
osv·2023-04-19
CVE-2023-20862 [MEDIUM] Spring Security logout not clearing security context
Spring Security logout not clearing security context
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the HttpSessionSecurityContextRepository. This vulnerability can keep users authenticated even after they performed logout. Users of affected versions should apply the following mitigation. 5.7.x users should upgrade to 5.7.8. 5.8.x users should upgrade to 5.8.3. 6.0.x users should upgrade to 6.0.3.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-20862 spring-security: Empty SecurityContext Is Not Properly Saved Upon Logout
bugzilla·2023-07-31·CVSS 6.3
CVE-2023-20862 [MEDIUM] CVE-2023-20862 spring-security: Empty SecurityContext Is Not Properly Saved Upon Logout
CVE-2023-20862 spring-security: Empty SecurityContext Is Not Properly Saved Upon Logout
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the HttpSessionSecurityContextRepository. This vulnerability can keep users authenticated even after they performed logout. Users of affected versions should apply the following mitigation. 5.7.x users should upgrade to 5.7.8. 5.8.x users should upgrade to 5.8.3. 6.0.x users should upgrade to 6.0.3.
https://spring.io/security/cve-2023-20862
https://security.netapp.com/advisory/ntap-20230526-0002/
Discussion:
Crea
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followed, with
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followe
2023-04-19
Published