漏洞信息详情
Vmware VMware Spring Security 权限许可和访问控制问题漏洞
漏洞简介
Vmware VMware Spring Security是美国威睿(Vmware)公司的一套为基于Spring的应用程序提供说明性安全保护的安全框架。
VMware Spring Security 中存在权限许可和访问控制问题漏洞。该漏洞源于攻击者可以通过Spring Security的多个SecurityContext更改绕过限制,以提升其权限。以下产品及版本受到影响:Spring Security 5.4.0 至 5.4.3 版本, Spring Security 5.3.0.RELEASE 至 5.3.7.RELEASE 版本, Spring Security 5.2.0.RELEASE 至 5.2.8.RELEASE 版本。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://tanzu.vmware.com/security/cve-2021-22112
参考网址
来源:MLIST
链接:https://lists.apache.org/thread.html/ra6389b1b82108a3b6bbcd22979f7665fd437c2a3408c9509a15a9ca1@%3Cpluto-dev.portals.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/redbd004a503b3520ae5746c2ab5e93fd7da807a8c128e60d2002cd9b@%3Cissues.nifi.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r3868207b967f926819fe3aa8d33f1666429be589bb4a62104a49f4e3@%3Cpluto-dev.portals.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r2cb05e499807900ba23e539643eead9c5f0652fd271f223f89da1804@%3Cpluto-scm.portals.apache.org%3E
来源:MISC
链接:https://tanzu.vmware.com/security/cve-2021-221122
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2021/02/19/7
来源:MLIST
链接:https://lists.apache.org/thread.html/r390783b3b1c59b978131ac08390bf77fbb3863270cbde59d5b0f5fde@%3Cpluto-dev.portals.apache.org%3E
来源:N/A
链接:https://www.oracle.com//security-alerts/cpujul2021.html
来源:MLIST
链接:https://lists.apache.org/thread.html/r37423ec7eea340e92a409452c35b649dce02fdc467f0b3f52086c177@%3Cpluto-dev.portals.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r89aa1b48a827f5641310305214547f1d6b2101971a49b624737c497f@%3Cpluto-dev.portals.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r413e380088c427f56102968df89ef2f336473e1b56b7d4b3a571a378@%3Cpluto-dev.portals.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/ra53677224fe4f04c2599abc88032076faa18dc84b329cdeba85d4cfc@%3Cpluto-scm.portals.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r163b3e4e39803882f5be05ee8606b2b9812920e196daa2a82997ce14@%3Cpluto-dev.portals.apache.org%3E
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuApr2021.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021101943
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021042548
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Spring-Security-privilege-escalation-via-Multiple-SecurityContext-Changes-34630
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpuapr2021.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021072758
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpuoct2021.html
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-22112
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021042314
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0656
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujul2021.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021072126
受影响实体
暂无
补丁
- VMware Spring Security 权限许可和访问控制问题漏洞的修复措施<!--2021-2-19-->
还没有评论,来说两句吧...