HomePivotal SoftwareCVE-2021-22112

CVE-2021-22112

HIGH
8.8CVSS
Published: 2021-02-23
Updated: 2024-11-21
AI Analysis

Description

Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to run with elevated privileges in a small portion of the application, the bug can be leveraged to extend those privileges to the rest of the application.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
NVD-CWE-noinfo

Metadata

Primary Vendor
PIVOTAL_SOFTWARE
Published
2/23/2021
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

pivotal_software : spring_securitypivotal_software : spring_securityvmware : spring_securityoracle : communications_element_manageroracle : communications_interactive_session_recorderoracle : communications_interactive_session_recorderoracle : communications_unified_inventory_managementoracle : hospitality_cruise_shipboard_property_management_systemoracle : insurance_policy_administrationoracle : insurance_policy_administrationoracle : mysql_enterprise_monitor

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2021-22112 | HIGH Severity | CVEDatabase.com | CVEDatabase.com