Tuesday, July 16, 2019

Vuln: Pivotal Spring Security CVE-2019-11272 Authentication Bypass Vulnerability



Pivotal Spring Security is prone to an authentication-bypass vulnerability

An attacker can exploit this issue to bypass security restrictions and perform unauthorized actions. This may aid in further attacks.

Spring Security 4.2 through 4.2.12 are vulnerable.
exploit



Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: vuldb@securityfocus.com.
solution



Solution:
Updates are available. Please see the references or vendor advisory for more information.

info



Bugtraq ID: 108877
Class: Design Error
CVE: CVE-2019-11272
Remote: Yes
Local: No
Published: Jun 19 2019 12:00AM
Updated: Jun 19 2019 12:00AM
Credit: Tim Buthe and Daniel Neagaru from mytaxi.
Vulnerable: Pivotal Software Spring Security 4.2.12
Pivotal Software Spring Security 4.2.11
Pivotal Software Spring Security 4.2.3
Pivotal Software Spring Security 4.2.2
Pivotal Software Spring Security 4.2.1
Pivotal Software Spring Security 4.2
Pivotal Software Spring Security 4.1.4
Pivotal Software Spring Security 4.1.3
Pivotal Software Spring Security 3.2.10
Pivotal Software Spring Security 3.2.9
Pivotal Software Spring Security 3.2.5
Pivotal Software Spring Security 3.2.4
Pivotal Software Spring Security 3.2
Pivotal Software Spring Security 3.1.7
Pivotal Software Spring Security 3.1.6
Pivotal Software Spring Security 4.0
Not Vulnerable: Pivotal Software Spring Security 4.2.13
references



from SecurityFocus Vulnerabilities https://ift.tt/2lz9N4x

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.