Description
Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.
Remediation
References
https://pivotal.io/security/cve-2018-1256
Related Vulnerabilities
CVE-2017-9787 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2020-2169 Vulnerability in maven package org.jenkins-ci.plugins:queue-cleanup
CVE-2015-2156 Vulnerability in maven package io.netty:netty-codec-http
CVE-2016-4800 Vulnerability in maven package org.eclipse.jetty:jetty-util
CVE-2020-2194 Vulnerability in maven package io.jenkins.plugins:echarts-api