Medium severity6.5NVD Advisory· Published Apr 21, 2022· Updated Jun 17, 2026
CVE-2022-22969
CVE-2022-22969
Description
Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session. This vulnerability exposes OAuth 2.0 Client applications only.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework.security.oauth:spring-security-oauth2Maven | >= 2.5.0.RELEASE, < 2.5.2.RELEASE | 2.5.2.RELEASE |
org.springframework.security.oauth:spring-security-oauth2Maven | >= 2.4.0.RELEASE, < 2.4.2.RELEASE | 2.4.2.RELEASE |
Affected products
2- Spring Security OAuth/Spring Security OAuthdescription
- ghsa-coordsRange: >= 2.5.0.RELEASE, < 2.5.2.RELEASE
Patches
Vulnerability mechanics
References
5- www.oracle.com/security-alerts/cpujul2022.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-c2cp-3xj9-97w9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-22969ghsaADVISORY
- tanzu.vmware.com/security/cve-2022-22969nvdVendor AdvisoryWEB
- spring.io/security/cve-2022-22969ghsaWEB
News mentions
0No linked articles in our index yet.