VYPR

Spring Security OAuth

by Cloudfoundry

CVEs (6)

  • CVE-2018-1260CriMay 11, 2018
    risk 0.64cvss 9.8epss 0.08

    Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization…

  • CVE-2016-4977HigMay 25, 2017
    risk 0.64cvss 8.8epss 0.79

    When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via the crafting of the…

  • CVE-2018-15758CriOct 18, 2018
    risk 0.56cvss 9.6epss 0.02

    Spring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to 2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0.16, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can craft a request…

  • CVE-2019-3778MedMar 7, 2019
    risk 0.46cvss 6.5epss 0.15

    Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can…

  • CVE-2022-22969MedApr 21, 2022
    risk 0.42cvss 6.5epss 0.01

    Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. A malicious user or attacker can send…

  • CVE-2019-11269MedJun 12, 2019
    risk 0.39cvss 5.4epss 0.09

    Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft…