CVE-2011-2731

EUVD-2022-2313
Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
vmwarespringsource_spring_security
𝑥
≤ 2.0.6
vmwarespringsource_spring_security
𝑥
≤ 3.0.5
vmwarespringsource_spring_security
2.0.0
vmwarespringsource_spring_security
2.0.1
vmwarespringsource_spring_security
2.0.2
vmwarespringsource_spring_security
2.0.3
vmwarespringsource_spring_security
2.0.4
vmwarespringsource_spring_security
2.0.5
vmwarespringsource_spring_security
3.0.0
vmwarespringsource_spring_security
3.0.1
vmwarespringsource_spring_security
3.0.2
vmwarespringsource_spring_security
3.0.3
vmwarespringsource_spring_security
3.0.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libspring-security-2.0-java
hardy
dne
lucid
dne
oneiric
ignored
precise
ignored
quantal
not-affected
raring
not-affected
saucy
not-affected
trusty
dne
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
dne
yakkety
dne
zesty
dne