Bug 1131359 (CVE-2014-3527)
Summary: | CVE-2014-3527 Spring Security CAS: Access control bypass via untrusted infomation usage in proxy ticket authentication | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Arun Babu Neelicattu <aneelica> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | acathrow, alonbl, bazulay, bmcclain, dblechte, ecohen, gklein, grocha, idith, iheim, michal.skrivanek, msrb, puntogil, Rhev-m-bugs, vkrizan, weli, yeylon, ylavi |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | spring-security-cas 3.2.5.RELEASE, spring-security-cas 3.1.7.RELEASE | Doc Type: | Bug Fix |
Doc Text: |
When using Spring Security's CAS Proxy ticket authentication, a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. A remote attacker could use this flaw to bypass any access control restrictions on which CAS services can authenticate to one another.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2014-08-20 04:24:31 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1131361, 1131362, 1131363 | ||
Bug Blocks: |
Description
Arun Babu Neelicattu
2014-08-19 06:00:54 UTC
Created springframework-security tracking bugs for this issue: Affects: fedora-all [bug 1131361] Upstream Commits: spring-security-cas/master https://github.com/spring-projects/spring-security/commit/934937d9c1dc20c396b96c08310b72cfa627acbf https://github.com/spring-projects/spring-security/commit/533b71b9b8e066865837933a90ca4210523906f0 spring-security-cas/3.1.x https://github.com/spring-projects/spring-security/commit/b78bd897cde12699facde01e1780039ee43ac858 spring-security-cas/3.2.x https://github.com/spring-projects/spring-security/commit/2cb99f079152ac05cee5c90457c7feb3bb2de55e Statement: This issue did not affect the versions of spring-security-cas provided by jasperreports-server-pro as shipped with Red Hat Enterprise Virtualization Manager 3 as they did not include support for CAS Proxy Service URL configuration via request parameters. springframework-security-3.1.7-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report. springframework-security-3.1.7-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. |