Vulnerability Name: | CVE-2018-1260 (CCN-143171) | ||||||||||||
Assigned: | 2017-12-06 | ||||||||||||
Published: | 2018-05-09 | ||||||||||||
Updated: | 2019-03-13 | ||||||||||||
Summary: | Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-94 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-1260 Source: CCN Type: IBM Security Bulletin 0731859 (Spectrum Symphony) Remote code execution vulnerability (CVE-2018-1260) affects IBM Spectrum Symphony 7.2.0.2 and 7.2.1 Source: BID Type: Third Party Advisory, VDB Entry 104158 Source: CCN Type: BID-104158 Pivotal Spring Security OAuth CVE-2018-1260 Remote Code Execution Vulnerability Source: REDHAT Type: Third Party Advisory RHSA-2018:1809 Source: REDHAT Type: Third Party Advisory RHSA-2018:2939 Source: XF Type: UNKNOWN pivotal-spring-cve20181260-code-exec(143171) Source: CCN Type: Pivotal Web site CVE-2018-1260: Remote Code Execution with spring-security-oauth2 Source: CONFIRM Type: Vendor Advisory https://pivotal.io/security/cve-2018-1260 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |