Description
Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread.
Remediation
References
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=677814
http://secunia.com/advisories/55155
http://support.springsource.com/security/cve-2011-2731
http://www.securitytracker.com/id/1029151
Related Vulnerabilities
CVE-2023-40311 Vulnerability in maven package org.opennms:opennms-webapp
CVE-2018-8003 Vulnerability in maven package org.apache.ambari:ambari-server
CVE-2020-8203 Vulnerability in maven package org.webjars.npm:lodash
CVE-2023-24442 Vulnerability in maven package org.jenkins-ci.plugins:github-pr-coverage-status
CVE-2021-20334 Vulnerability in npm package mongodb-js-metrics