Loading HuntDB...

GHSA-q4q2-93pw-qwgf

GitHub Security Advisory

Issuer validation regression in Spring Cloud SSO Connector

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.

### Mitigation
Users of affected versions should apply the following mitigation:
* Releases that have fixed this issue include:</p><ul><li>Spring Cloud SSO Connector: 2.1.3</li></ul>
* Alternatively, you can perform <u>one</u> of the following workarounds:</p><ul><li>Bind your resource server to the SSO service plan via a service instance binding</li><li>Set “sso.connector.cloud.available=true” within your Spring application properties</li></ul>

Affected Packages

Maven io.pivotal.spring.cloud:spring-cloud-sso-connector
Affected versions: 2.1.2.RELEASE (fixed in 2.1.3.RELEASE)

Related CVEs

Key Information

GHSA ID
GHSA-q4q2-93pw-qwgf
Published
May 13, 2022 1:07 AM
Last Modified
March 4, 2024 8:48 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
io.pivotal.spring.cloud:spring-cloud-sso-connector
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 7, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.