First published: Sun Apr 29 2018(Updated: )
Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.
Credit: security_alert@emc.com security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/io.pivotal.spring.cloud:spring-cloud-sso-connector | =2.1.2.RELEASE | 2.1.3.RELEASE |
=2.1.2 | ||
Vmware Spring Cloud Sso Connector | =2.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.