CVE-2011-2731

Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
vmwarespringsource_spring_security
𝑥
≤ 2.0.6
vmwarespringsource_spring_security
𝑥
≤ 3.0.5
vmwarespringsource_spring_security
2.0.0
vmwarespringsource_spring_security
2.0.1
vmwarespringsource_spring_security
2.0.2
vmwarespringsource_spring_security
2.0.3
vmwarespringsource_spring_security
2.0.4
vmwarespringsource_spring_security
2.0.5
vmwarespringsource_spring_security
3.0.0
vmwarespringsource_spring_security
3.0.1
vmwarespringsource_spring_security
3.0.2
vmwarespringsource_spring_security
3.0.3
vmwarespringsource_spring_security
3.0.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libspring-security-2.0-java
zesty
dne
yakkety
dne
xenial
dne
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
ignored
oneiric
ignored
lucid
dne
hardy
dne