Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x637-x8p3-5p22

Опубликовано: 20 мар. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Improper Authentication in Spring Authorization Server

Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients.

Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant.

An application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.

Пакеты

Наименование

org.springframework.security:spring-security-oauth2-authorization-server

maven
Затронутые версииВерсия исправления

< 1.1.6

1.1.6

Наименование

org.springframework.security:spring-security-oauth2-authorization-server

maven
Затронутые версииВерсия исправления

>= 1.2.0, < 1.2.3

1.2.3

EPSS

Процентиль: 26%
0.00093
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-287
CWE-470

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 2 года назад

Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant. An application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.

CVSS3: 6.1
nvd
почти 2 года назад

Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant. An application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.

EPSS

Процентиль: 26%
0.00093
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-287
CWE-470