CVE Feed

    Dashboard / CVE / CVE-2021-22112

    CVE-2021-22112

    Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to run with elevated privileges in a small portion of the application, the bug can be leveraged to extend those privileges to the rest of the application.

    Published:Feb 19, 2021
    Last Modified:Nov 21, 2024
    EPS:Feb 23, 2021
    EPSS Score:0.00979
    CVSS Score:8.8

    Affected Products

    Vendor
    Oracle
    Product
    Communications Element Manager
    Vendor
    Oracle
    Product
    Communications Interactive Session Recorder
    Vendor
    Oracle
    Product
    Communications Unified Inventory Management
    Vendor
    Oracle
    Product
    Hospitality Cruise Shipboard Property Management System
    Vendor
    Oracle
    Product
    Insurance Policy Administration
    Vendor
    Oracle
    Product
    Mysql Enterprise Monitor
    Vendor
    Pivotal Software
    Product
    Spring Security
    Vendor
    Vmware
    Product
    Spring Security

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High