3.6.5
4 years ago
1 months ago
Known vulnerabilities in the com.sap.cloud.security:spring-security package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Improper Privilege Management due to improper validation of JSON Web Token (JWT) signatures. An attacker can escalate privileges and obtain arbitrary permissions within the application by exploiting this flaw. How to fix Improper Privilege Management? Upgrade | [,2.17.0)[3.0.0,3.3.0) |