Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pivotal Spring Cloud SSO Connector 安全漏洞
Vulnerability Description
Pivotal Spring Cloud SSO Connector是美国Pivotal Software公司的一款用于Cloud Foundry的一款单点登录连接器。 Pivotal Spring Cloud SSO Connector 2.1.2版本中存在安全漏洞。攻击者可利用该漏洞对未绑定的资源服务器进行身份验证。
CVSS Information
N/A
Vulnerability Type
N/A