CVE-2020-5408

Description

Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.468

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-5408,CVE-2020-5407 are fixed in Spring-security-core 5.3.2Windows
Vulnerabilities CVE-2020-5408,CVE-2020-5407 are fixed in Spring-security-core 5.2.4Windows
Vulnerabilities CVE-2020-5408 are fixed in Spring-security-core 5.1.10Windows
Vulnerabilities CVE-2020-5408 are fixed in Spring-security-core 5.0.16Windows
Vulnerabilities CVE-2020-5408 are fixed in Spring-security-core 4.2.16Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.4Windows
Vulnerabilities CVE-2020-5408,CVE-2020-5407 are fixed in Spring-security-core for Linux 5.3.2Linux
Vulnerabilities CVE-2020-5408,CVE-2020-5407 are fixed in Spring-security-core for Linux 5.2.4Linux
Vulnerabilities CVE-2020-5408 are fixed in Spring-security-core for Linux 5.1.10Linux
Vulnerabilities CVE-2020-5408 are fixed in Spring-security-core for Linux 5.0.16Linux
Vulnerabilities CVE-2020-5408 are fixed in Spring-security-core for Linux 4.2.16Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234