Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.
Spring Cloud SSO Connector:
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 2.1.x | 2.1.3 | OSS |
Alternatively, you can perform one of the following workarounds:
The issue was identified and responsibly reported by the Pivotal SSO Service team.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy