Description
Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.
Remediation
References
https://pivotal.io/security/cve-2018-1256
Related Vulnerabilities
CVE-2020-2122 Vulnerability in maven package org.jenkins-ci.plugins:brakeman
CVE-2019-16569 Vulnerability in maven package org.jenkins-ci.plugins:mantis
CVE-2022-28220 Vulnerability in maven package org.apache.james.protocols:protocols-api
CVE-2021-21172 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-36060 Vulnerability in npm package matrix-react-sdk