Issuer validation regression in Spring Cloud SSO Connector
        
  High severity
        
          GitHub Reviewed
      
        Published
          May 13, 2022 
          to the GitHub Advisory Database
          •
          Updated Mar 4, 2024 
      
  
Package
Affected versions
= 2.1.2.RELEASE
  Patched versions
2.1.3.RELEASE
  Description
        Published by the National Vulnerability Database
      May 7, 2018 
    
  
        Published to the GitHub Advisory Database
      May 13, 2022 
    
  
        Reviewed
      Jan 8, 2024 
    
  
        Last updated
      Mar 4, 2024 
    
  
Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.
Mitigation
Users of affected versions should apply the following mitigation:
References