CVE-2018-15801 is an authorization bypass vulnerability affecting Spring Security versions 5.1.x prior to 5.1.2, specifically impacting VMware Spring Framework. It allows a malicious user to forge signed JSON Web Tokens (JWTs) with a malicious issuer URL, which could then be accepted as valid for an honest issuer, provided both use the same private key for signing. This vulnerability has a CVSS score of 7.4 (High), indicating a network-based attack with high impact on confidentiality and integrity, but requires high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.1.0, < 5.1.2CPE matchmatch criteria | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.