{"id":"GHSA-q4q2-93pw-qwgf","summary":"Issuer validation regression in Spring Cloud SSO Connector","details":"Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.\n\n### Mitigation\nUsers of affected versions should apply the following mitigation:\n* Releases that have fixed this issue include:\u003c/p\u003e\u003cul\u003e\u003cli\u003eSpring Cloud SSO Connector: 2.1.3\u003c/li\u003e\u003c/ul\u003e\n* Alternatively, you can perform \u003cu\u003eone\u003c/u\u003e of the following workarounds:\u003c/p\u003e\u003cul\u003e\u003cli\u003eBind your resource server to the SSO service plan via a service instance binding\u003c/li\u003e\u003cli\u003eSet “sso.connector.cloud.available=true” within your Spring application properties\u003c/li\u003e\u003c/ul\u003e\n\n","aliases":["CVE-2018-1256"],"modified":"2024-03-04T20:48:59Z","published":"2022-05-13T01:07:05Z","database_specific":{"nvd_published_at":"2018-05-07T16:22:00Z","cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-01-08T21:04:11Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1256"},{"type":"WEB","url":"https://github.com/pivotal-cf/spring-cloud-sso-connector/commit/ef647a2acf2363c6018e8543d665ac8862593372"},{"type":"WEB","url":"https://pivotal.io/security/cve-2018-1256"}],"affected":[{"package":{"name":"io.pivotal.spring.cloud:spring-cloud-sso-connector","ecosystem":"Maven","purl":"pkg:maven/io.pivotal.spring.cloud/spring-cloud-sso-connector"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.2.RELEASE"},{"fixed":"2.1.3.RELEASE"}]}],"versions":["2.1.2.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q4q2-93pw-qwgf/GHSA-q4q2-93pw-qwgf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}