Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cvc6-q2cp-2xhw

Опубликовано: 22 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Spring Security has Potential Security Misconfiguration when Using withIssuerLocation

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator separately, for example by calling setJwtValidator. This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

Пакеты

Наименование

org.springframework.security:spring-security-oauth2-jose

maven
Затронутые версииВерсия исправления

>= 6.3.0, <= 6.3.14

Отсутствует

Наименование

org.springframework.security:spring-security-oauth2-jose

maven
Затронутые версииВерсия исправления

>= 6.4.0, <= 6.4.14

Отсутствует

Наименование

org.springframework.security:spring-security-oauth2-jose

maven
Затронутые версииВерсия исправления

>= 6.5.0, <= 6.5.9

6.5.10

Наименование

org.springframework.security:spring-security-oauth2-jose

maven
Затронутые версииВерсия исправления

>= 7.0.0, <= 7.0.4

7.0.5

EPSS

Процентиль: 11%
0.00203
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

CVSS3: 5.3
redhat
4 месяца назад

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

CVSS3: 5.3
nvd
4 месяца назад

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

CVSS3: 5.3
debian
4 месяца назад

Vulnerability in Spring Spring Security. When an application configure ...

EPSS

Процентиль: 11%
0.00203
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20