Description
Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread.
Remediation
References
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=677814
http://secunia.com/advisories/55155
http://support.springsource.com/security/cve-2011-2731
http://www.securitytracker.com/id/1029151
Related Vulnerabilities
CVE-2022-45397 Vulnerability in maven package org.jenkins-ci.plugins:osf-builder-suite-xml-linter
CVE-2022-36885 Vulnerability in maven package com.coravy.hudson.plugins.github:github
CVE-2021-39233 Vulnerability in maven package org.apache.ozone:ozone-main
CVE-2019-10350 Vulnerability in maven package org.jenkins-ci.plugins:port-allocator
CVE-2018-1000010 Vulnerability in maven package org.jvnet.hudson.plugins:dry