CVE-2018-1256 describes a regression in Spring Cloud SSO Connector version 2.1.2 that disables issuer validation in resource servers not bound to the SSO service. This allows a remote attacker to authenticate to unbound resource servers using tokens from a different SSO service plan, specifically impacting VMware Spring Cloud SSO Connector deployments. The vulnerability carries a high CVSS score of 8.1, indicating a critical risk with network-based attacks, high impact on confidentiality, integrity, and availability, but also high attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.2CPE matchmatch criteria | cpe:2.3:a:vmware:spring_cloud_sso_connector:2.1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.