Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22258

Опубликовано: 20 мар. 2024
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients.

Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant.

An application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.

EPSS

Процентиль: 27%
0.00093
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-470

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 2 года назад

Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant. An application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.

CVSS3: 6.1
github
почти 2 года назад

Improper Authentication in Spring Authorization Server

EPSS

Процентиль: 27%
0.00093
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-470