SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. Affected versions: Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.7.25CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 5.8.0, < 5.8.27CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 6.3.0, < 6.3.18CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 6.4.0, < 6.4.18CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 6.5.0, < 6.5.11CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.