Логотип exploitDog
bind:CVE-2024-22258
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-22258

Количество 3

Количество 3

ubuntu логотип

CVE-2024-22258

почти 2 года назад

Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant. An application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-22258

почти 2 года назад

Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant. An application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-x637-x8p3-5p22

почти 2 года назад

Improper Authentication in Spring Authorization Server

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-22258

Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant. An application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.

CVSS3: 6.1
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-22258

Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant. An application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-x637-x8p3-5p22

Improper Authentication in Spring Authorization Server

CVSS3: 6.1
0%
Низкий
почти 2 года назад

Уязвимостей на страницу