← Back
Web Application
CVE-2018-1258 high CVSS 8.8

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauth...

Summary

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.

AI summary openai / gpt-4o

Spring Framework 5.0.5と任意のバージョンのSpring Securityを組み合わせると、メソッドセキュリティにおいて認可バイパスの脆弱性が発生します。これにより、攻撃者は制限されるべきメソッドに不正にアクセスできます。この脆弱性は高い重要度を持ち、早急な対応が求められます。
❓ What is the problem
Spring Framework 5.0.5におけるメソッドセキュリティの認可バイパス。
📍 Affected scope
Spring Framework 5.0.5とSpring Security任意のバージョン。
🔥 Severity
認可バイパスにより、攻撃者が制限されたメソッドにアクセス可能になる。リスクが高い。
🔧 How to fix
パッチを適用するため、OracleやRed Hatの提供する更新を実施する。
🛡️ Workaround
パッチ適用までの間、アクセス制御の監視を強化し、不正アクセスを検知する。
🔍 Detection
ログを解析し、不正アクセスの痕跡を確認する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →