Access Restriction Bypass Affecting org.springframework.security:spring-security-cas package, versions [3.2.0,3.2.5.RELEASE)[3.1.0,3.1.7.RELEASE)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.81% (76th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-30173
  • published25 Dec 2016
  • disclosed25 Dec 2016
  • creditDavid Ohsie

Introduced: 25 Dec 2016

CVE-2014-3527  (opens in a new tab)
CWE-284  (opens in a new tab)

Overview

org.springframework.security:spring-security-cas When using Spring Security's CAS Proxy ticket authentication, a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. A remote attacker could use this flaw to bypass any access control restrictions on which CAS services can authenticate to one another.

CVSS Base Scores

version 3.1