Lucene search

K
osvGoogleOSV:GHSA-4644-HG35-55M9
HistoryMay 17, 2022 - 4:59 a.m.

Concurrent Execution using Shared Resource with Improper Synchronization in Spring Security

2022-05-1704:59:50
Google
osv.dev
14
concurrent execution
shared resource
improper synchronization
race condition
runasmanager mechanism
vmware
springsource
spring security
authentication
privileges
crafted thread

EPSS

0.003

Percentile

68.4%

Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread.

EPSS

0.003

Percentile

68.4%