Spring Security OAuth vulnerable to remote code execution (RCE)
Critical severity
GitHub Reviewed
Published
Oct 18, 2018
to the GitHub Advisory Database
•
Updated May 14, 2024
Package
Affected versions
>= 2.3.0, < 2.3.3
>= 2.2.0, < 2.2.2
>= 2.1.0, < 2.1.2
>= 2.0.0, < 2.0.15
>= 1.0.0, <= 1.0.5
Patched versions
2.3.3
2.2.2
2.1.2
2.0.15
Description
Published to the GitHub Advisory Database
Oct 18, 2018
Reviewed
Jun 16, 2020
Last updated
May 14, 2024
Spring Security OAuth versions prior to 2.3.3, prior to 2.2.2, prior to 2.1.2, and prior to 2.0.15 contain a remote code execution vulnerability. An attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.
References