CVE-2011-2731
Concurrent Execution using Shared Resource with Improper Synchronization in Spring Security
EPSS 1.2%
描述
Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread.
如何修補 CVE-2011-2731
要修補 CVE-2011-2731,請將受影響套件升級到下列已修補版本。
- Maven/org.springframework.security:spring-security-core—升級至 2.0.7 或更新版本
CVE-2011-2731 正在被利用嗎?
低 — EPSS 為 1.2%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.0.7