CVE-2018-1258: High severity Pivotal Software Spring Security vulnerability
A flaw was found in Spring Security in combination with Spring Framework versions prior to 5.0.6 contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
References: https://pivotal.io/security/cve-2018-1258
Other sources
Pivotal Spring Framework Spring Security could allow a remote attacker to bypass security restrictions. By sending a specially-crafted request, an attacker could exploit this vulnerability to gain unauthorized access to methods that should be restricted.
— IBM
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
— GitHub
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1258?
CVE-2018-1258 has been classified with a critical severity due to its potential to allow unauthorized access.
How do I fix CVE-2018-1258?
To fix CVE-2018-1258, upgrade Pivotal Spring Framework to version 5.0.6 or later.
What applications are affected by CVE-2018-1258?
CVE-2018-1258 affects applications using Pivotal Spring Framework version 5.0.5 and related security components.
What type of vulnerability is CVE-2018-1258?
CVE-2018-1258 is a security bypass vulnerability that allows attackers to gain unauthorized access to protected methods.
Who is impacted by CVE-2018-1258?
Organizations using vulnerable versions of Pivotal Spring Framework are at risk and should take immediate action to address it.