REDHAT-BUG-2460487: High severity Spring Spring Security vulnerability
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2460487?
The severity of REDHAT-BUG-2460487 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2460487?
To fix REDHAT-BUG-2460487, upgrade to the latest version of Spring Security that addresses this vulnerability.
What does REDHAT-BUG-2460487 affect?
REDHAT-BUG-2460487 affects the Spring Security framework, specifically its handling of malformed X.509 certificate CN values.
What can happen if REDHAT-BUG-2460487 is exploited?
Exploitation of REDHAT-BUG-2460487 can allow an attacker to impersonate another user by reading incorrect username values from X.509 certificates.
When was REDHAT-BUG-2460487 published?
REDHAT-BUG-2460487 was published on April 22, 2026.