CVE-2023-34042
published 2024-02-05CVE-2023-34042: The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.22%
12.1th percentile
The spring-security.xsd file inside the
spring-security-config jar is world writable which means that if it were
extracted it could be written by anyone with access to the file system.
While there are no known exploits, this is an example of “CWE-732:
Incorrect Permission Assignment for Critical Resource” and could result
in an exploit. Users should update to the latest version of Spring
Security to mitigate any future exploits found around this issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | spring_security | — | — |
| vmware | spring_security | — | — |
| vmware | spring_security | — | — |
| vmware | spring_security | >= 5.8.4 < 5.8.7 | 5.8.7 |
| vmware | spring_security | >= 6.0.4 < 6.0.7 | 6.0.7 |
| vmware | spring_security | >= 6.1.1 < 6.1.4 | 6.1.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
spring-security-config: Incorrect Permission Assignment for spring-security.xsd
vendor_redhat·2024-02-05·CVSS 4.1
CVE-2023-34042 [MEDIUM] CWE-732 spring-security-config: Incorrect Permission Assignment for spring-security.xsd
spring-security-config: Incorrect Permission Assignment for spring-security.xsd
The spring-security.xsd file inside the
spring-security-config jar is world writable which means that if it were
extracted it could be written by anyone with access to the file system.
While there are no known exploits, this is an example of “CWE-732:
Incorrect Permission Assignment for Critical Resource” and could result
in an exploit. Users should update to the latest version of Spring
Security to mitigate any future exploits found around this issue.
A flaw was found in the Spring-security-config jar file. The spring-security.xsd file inside the spring-security-config jar is world-writable, which means that if it were extracted, it could be written by anyone with access to the file system.
Mitigation: Miti
OSV
Spring Security's spring-security.xsd file is world writable
osv·2024-02-06
CVE-2023-34042 [MEDIUM] Spring Security's spring-security.xsd file is world writable
Spring Security's spring-security.xsd file is world writable
The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access to the file system.
While there are no known exploits, this is an example of “CWE-732: Incorrect Permission Assignment for Critical Resource” and could result in an exploit. Users should update to the latest version of Spring Security to mitigate any future exploits found around this issue.
GHSA
Spring Security's spring-security.xsd file is world writable
ghsa·2024-02-06
CVE-2023-34042 [MEDIUM] CWE-732 Spring Security's spring-security.xsd file is world writable
Spring Security's spring-security.xsd file is world writable
The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access to the file system.
While there are no known exploits, this is an example of “CWE-732: Incorrect Permission Assignment for Critical Resource” and could result in an exploit. Users should update to the latest version of Spring Security to mitigate any future exploits found around this issue.
No detection rules found.
No public exploits indexed.
2024-02-05
Published