CVE-2023-20862 - Local Privilege Escalation

Severity: None2023-06-07

Security Advisories

Abstract

In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the HttpSessionSecurityContextRepository. This vulnerability can keep users authenticated even after they performed logout. Users of affected versions should apply the following mitigation. 5.7.x users should upgrade to 5.7.8. 5.8.x users should upgrade to 5.8.3. 6.0.x users should upgrade to 6.0.3.

The Oxygen products incorporate Spring Security as a third-party library. This advisory was opened to address the potential impact of this third-party library vulnerability.

Affected Products/Versions

ProductSeverityFixed Release Availability
Oxygen Content Fusion v5.1 and olderNone Oxygen Content Fusion 5.1.1 build 2023072112
Oxygen Feedback v3.0.1 and olderNone Oxygen Feedback 3.0.2 build 2023072015

Mitigation

None

Detail

CVE-2023-20862

Severity: Critical

CVSS Score: 9.8

The Spring Security third-party library used by Oxygen XML products is an affected version mentioned in CVE-2023-20862 vulnerability description. However, the Oxygen products do not use the vulnerable code. For that reason, Oxygen XML products are not affected.

Revision History

2023-07-26 Starting with Oxygen Content Fusion version 5.1.1 build 2023072112, the Spring Security was updated to version 5.7.8, which includes a fix for CVE-2023-20862.

2023-07-26 Starting with Oxygen Feedback version 3.0.2 build 2023072015, the Spring Security was updated to version 5.7.8, which includes a fix for CVE-2023-20862.

List of Security Advisories