Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c2cp-3xj9-97w9

Опубликовано: 22 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Denial of service in Spring Security OAuth2

Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session. This vulnerability exposes OAuth 2.0 Client applications only.

Пакеты

Наименование

org.springframework.security.oauth:spring-security-oauth2

maven
Затронутые версииВерсия исправления

>= 2.5.0.RELEASE, < 2.5.2.RELEASE

2.5.2.RELEASE

Наименование

org.springframework.security.oauth:spring-security-oauth2

maven
Затронутые версииВерсия исправления

>= 2.4.0.RELEASE, < 2.4.2.RELEASE

2.4.2.RELEASE

EPSS

Процентиль: 71%
0.00665
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

<Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session. This vulnerability exposes OAuth 2.0 Client applications only.

EPSS

Процентиль: 71%
0.00665
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400