Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1260

Опубликовано: 09 мая 2018
Источник: redhat
CVSS3: 6.3
EPSS Средний

Описание

Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Fuse Integration Service 2spring-security-oauthAffected
Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R8FixedRHSA-2018:293917.10.2018
Text-Only RHOARFixedRHSA-2018:180907.06.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-267
https://bugzilla.redhat.com/show_bug.cgi?id=1584376spring-security-oauth: remote code execution in the authorization process

EPSS

Процентиль: 98%
0.61665
Средний

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.

CVSS3: 9.8
github
больше 7 лет назад

Spring Security OAuth vulnerable to remote code execution (RCE)

EPSS

Процентиль: 98%
0.61665
Средний

6.3 Medium

CVSS3