CVE-2021-22112
Privilege escalation in spring security
8.8
HIGH
CVSS 3.1
EPSS 3.2%
描述
Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to run with elevated privileges in a small portion of the application, the bug can be leveraged to extend those privileges to the rest of the application.
如何修補 CVE-2021-22112
要修補 CVE-2021-22112,請將受影響套件升級到下列已修補版本。
- —升級至 5.4.4 或更新版本
- —升級至 5.4.4 或更新版本
CVE-2021-22112 正在被利用嗎?
低 — EPSS 為 3.2%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 5.4.0, < 5.4.4
- >= 5.4.0, < 5.4.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |