GHSA-rrpm-pj7p-7j9q

    Dashboard / Vulnerabilities / GHSA-rrpm-pj7p-7j9q

    GHSA-rrpm-pj7p-7j9q

    Published: 18 Oct 2018Last Modified: 14 May 2024
    Aliases:

    Summary: Spring Security OAuth vulnerable to remote code execution (RCE)

    Details: Spring Security OAuth versions prior to 2.3.3, prior to 2.2.2, prior to 2.1.2, and prior to 2.0.15 contain a remote code execution vulnerability. An attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.

    Affected packages

    Package

    Name: org.springframework.security.oauth:spring-security-oauth2

    Purl: pkg:maven/org.springframework.security.oauth/spring-security-oauth2

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 2.3.0
    Fixed -2.3.3

    Affected versions

    2.3.0.RELEASE
    2.3.1.RELEASE
    2.3.2.RELEASE

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High