Back

CRITICAL

spring-security-oauth: remote code execution in the authorization process

Published May 11, 2018

Description

Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dell
Published May 11, 2018
Updated Sep 17, 2024
Reserved Dec 6, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 9, 2018
GHSA-RRPM-PJ7P-7J9Q