Bug 1584376 (CVE-2018-1260)

Summary: CVE-2018-1260 spring-security-oauth: remote code execution in the authorization process
Product: [Other] Security Response Reporter: Laura Pardo <lpardo>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: claprun, marthasimons9999
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: spring-security-oauth 2.3.3, spring-security-oauth 2.2.2, spring-security-oauth 2.1.2, spring-security-oauth 2.0.15 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-21 20:04:37 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1584382    

Description Laura Pardo 2018-05-30 18:47:57 UTC
A flaw was found in Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.


References:
https://pivotal.io/security/cve-2018-1260

Comment 2 claprun@redhat.com 2018-06-01 08:41:46 UTC
Shouldn't this be marked as critical as that's how the Pivotal CVE is classified?

Comment 3 errata-xmlrpc 2018-06-07 08:26:08 UTC
This issue has been addressed in the following products:

  Red Hat Openshift Application Runtimes (text-only advisories)

Via RHSA-2018:1809 https://access.redhat.com/errata/RHSA-2018:1809

Comment 4 errata-xmlrpc 2018-10-17 19:30:01 UTC
This issue has been addressed in the following products:

  Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R8

Via RHSA-2018:2939 https://access.redhat.com/errata/RHSA-2018:2939

Comment 5 marthasimons2 2018-10-22 11:13:00 UTC
Thanka for greate job Red Hat Fuse Intergration Services 2.0

Via RHSA-2018:2940 https://goo.gl/hKpzJK