CVE Vulnerabilities

CVE-2020-5407

Improper Verification of Cryptographic Signature

Published: May 13, 2020 | Modified: Nov 07, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. When using the spring-security-saml2-service-provider component, a malicious user can carefully modify an otherwise valid SAML response and append an arbitrary assertion that Spring Security will accept as valid.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Spring_security Pivotal_software 5.2.0 (including) 5.2.4 (excluding)
Spring_security Pivotal_software 5.3.0 (including) 5.3.2 (excluding)
Libspring-security-2.0-java Ubuntu precise *
Libspring-security-2.0-java Ubuntu trusty *

References