Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreApplications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition.
An attacker with a valid one-time token can send concurrent requests to the authentication endpoint, allowing the single-use token to be consumed multiple times and establishing multiple authenticated sessions.
The default InMemoryOneTimeTokenService is thread-safe and not affected by this vulnerability.
Spring Security:
| Fix version | Availability |
|---|---|
| 7.0.5 | OSS |
| 6.5.10 | OSS |
| 6.4.16 | Enterprise Support Only |
No further mitigation steps are necessary.
The issue was identified and responsibly reported by Jinyeong Seol (@Seol-JY).
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy