CVE-2018-1256: Issuer validation regression in Spring Cloud SSO Connector

HIGH | APRIL 30, 2018 | CVE-2018-1256

Description

Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.

Affected Spring Products and Versions

Spring Cloud SSO Connector:

  • 2.1.2 - 2.1.2

Mitigation

Affected version(s) Fix version Availability
2.1.x 2.1.3 OSS

Alternatively, you can perform one of the following workarounds:

  • Bind your resource server to the SSO service plan via a service instance binding
  • Set “sso.connector.cloud.available=true” within your Spring application properties

Credit

The issue was identified and responsibly reported by the Pivotal SSO Service team.

History

  • 2018-04-30: Initial vulnerability report published
  • 2026-07-09: Formatting improvements.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all