The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade io.pivotal.spring.cloud:spring-cloud-sso-connector
to version 2.1.3 or higher.
io.pivotal.spring.cloud:spring-cloud-sso-connector is a Spring Cloud Connector for use with the Pivotal Single Sign-On Service on Cloud Foundry.
Affected versions of this package are vulnerable to Authentication Bypass. It disables issuer validation in resource servers that are not bound to the SSO service. A remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.