5.1
CVSSv2

CVE-2011-2731

Published: 05/12/2012 Updated: 24/10/2013
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security prior to 2.0.7 and 3.0.x prior to 3.0.6 stores the Authentication object in the shared security context, which allows malicious users to gain privileges via a crafted thread.

Vulnerable Product Search on Vulmon Subscribe to Product

vmware springsource spring security 2.0.4

vmware springsource spring security 2.0.5

vmware springsource spring security 2.0.2

vmware springsource spring security 2.0.3

vmware springsource spring security

vmware springsource spring security 2.0.0

vmware springsource spring security 2.0.1

vmware springsource spring security 3.0.3

vmware springsource spring security 3.0.4

vmware springsource spring security 3.0.0

vmware springsource spring security 3.0.1

vmware springsource spring security 3.0.2

Vendor Advisories

Debian Bug report logs - #670901 Spring: Multiple security issues Package: libspring-security-20-java; Maintainer for libspring-security-20-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Mon, 30 Apr 2012 07:57:05 UTC ...