CVE-2022-31690: High severity spring security vulnerability

Published Oct 31, 2022
·
Updated

A flaw was found in the Spring Security framework. Spring Security could allow a remote attacker to gain elevated privileges on the system. By modifying a request initiated by the Client (via the browser) to the Authorization Server, an attacker can gain elevated privileges on the system.

Other sources

Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a request initiated by the Client (via the browser) to the Authorization Server which can lead to a privilege escalation on the subsequent approval. This scenario can happen if the Authorization Server responds with an OAuth2 Access Token Response containing an empty scope list (per RFC 6749, Section 5.1) on the subsequent request to the token endpoint to obtain the access token.

VMware Tanzu Spring Security could allow a remote attacker to gain elevated privileges on the system. By modifying a request initiated by the Client (via the browser) to the Authorization Server, an attacker could exploit this vulnerability to gain elevated privileges on the system.

IBM

Affected Software

7 affected componentsFixes available
redhat/jenkins<0:2.387.1.1680701869-1.el8
0:2.387.1.1680701869-1.el8
redhat/Spring Security<5.7.5
5.7.5
redhat/Spring Security<5.6.9
5.6.9
VMware Spring Security>=5.6.0<5.6.9
VMware Spring Security>=5.7.0<5.7.5
NetApp Active Iq Unified Manager Vmware Vsphere
NetApp Active Iq Unified Manager Windows

Event History

Oct 31, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Jan 19, 2023
Data Sourced
via Red Hat·05:06 AM
DescriptionSeverityAffected Software
Mar 20, 2024
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-31690?

CVE-2022-31690 is a vulnerability in the Spring Security framework that allows for privilege escalation.

2

Which versions of Spring Security are affected by CVE-2022-31690?

Versions 5.7 to 5.7.5 and 5.6 to 5.6.9 of Spring Security are affected by CVE-2022-31690.

3

How can a malicious user exploit CVE-2022-31690?

A malicious user can modify a request initiated by the Client to the Authorization Server in certain conditions to exploit CVE-2022-31690.

4

What is the severity of CVE-2022-31690?

CVE-2022-31690 has a severity rating of 8.1 (High).

5

How can I fix CVE-2022-31690?

To fix CVE-2022-31690, upgrade to Spring Security version 5.7.5 or 5.6.9 depending on the current version you are using.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203