CVE-2023-20873: Critical severity VMware Spring Boot vulnerability
In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass.
References:
https://spring.io/security/cve-2023-20873 https://github.com/spring-projects/spring-boot/commit/307f3c339912466e78fcdac648fff95a4edea573 https://github.com/spring-projects/spring-boot/commit/3522714c13b47af03bf42e7f2d5994af568cb1a7 https://github.com/spring-projects/spring-boot/issues/35085 https://github.com/spring-projects/spring-boot/releases/tag/v2.7.11
Other sources
In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to 2.7.11+. Users of older, unsupported versions should upgrade to 3.0.6+ or 2.7.11+.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.springframework.boot:spring-boot-actuator-autoconfigureto a version that resolves this vulnerability.Fixed in 2.5.15 - Upgrade
Upgrade
maven/org.springframework.boot:spring-boot-actuator-autoconfigureto a version that resolves this vulnerability.Fixed in 2.6.15 - Upgrade
Upgrade
maven/org.springframework.boot:spring-boot-actuator-autoconfigureto a version that resolves this vulnerability.Fixed in 2.7.11 - Upgrade
Upgrade
maven/org.springframework.boot:spring-boot-actuator-autoconfigureto a version that resolves this vulnerability.Fixed in 3.0.6 - Upgrade
Upgrade
redhat/spring-bootto a version that resolves this vulnerability.Fixed in 2.5.15 - Upgrade
Upgrade
redhat/spring-bootto a version that resolves this vulnerability.Fixed in 2.6.15 - Upgrade
Upgrade
redhat/spring-bootto a version that resolves this vulnerability.Fixed in 2.7.11 - Upgrade
Upgrade
redhat/spring-bootto a version that resolves this vulnerability.Fixed in 3.0.6 - Upgrade
Upgrade
spring-bootto a version that resolves this vulnerability.Fixed in 2.7.11+ - Upgrade
Upgrade
spring-bootto a version that resolves this vulnerability.Fixed in 3.0.6+
Event History
Frequently Asked Questions
What is CVE-2023-20873?
CVE-2023-20873 is a vulnerability in Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions that could lead to a security bypass.
How severe is CVE-2023-20873?
CVE-2023-20873 has a severity rating of 9.8 out of 10, making it a critical vulnerability.
How can I mitigate CVE-2023-20873?
To mitigate CVE-2023-20873, users of affected versions should upgrade to Spring Boot 3.0.6+ or 2.7.11+ depending on the version being used.
Where can I find more information about CVE-2023-20873?
Additional information about CVE-2023-20873 can be found at the following references: https://security.netapp.com/advisory/ntap-20230601-0009/ and https://spring.io/blog/2023/05/18/spring-boot-2-5-15-and-2-6-15-available-now