org.springframework.security.oauth:spring-security-oauth2
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.springframework.security.oauth:spring-security-oauth2page 1 of 1
- CVE-2016-4977CRITICALCVSS 8.8EG 9.0fixed in 2.0.10 or 1.0.5, by version range2017-05-25
vulnerable: 1.0.0.RELEASE, 1.0.1.RELEASE, 1.0.2.RELEASE, 1.0.3.RELEASE, 1.0.4.RELEASE
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote co…
- CVE-2018-1260CRITICALCVSS 9.8EG 9.8fixed in 2.3.3, 2.2.2, 2.1.2 or 2.0.15, by version range2018-05-11
vulnerable: 1.0.0.RELEASE ... 1.0.5.RELEASE (6 versions)
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an author…
- CVE-2018-15758CRITICALCVSS 9.6EG 9.6fixed in 2.0.16, 2.1.3, 2.2.3.RELEASE or 2.3.4.RELEASE, by version range2018-10-18
vulnerable: 2.3.0.RELEASE, 2.3.1.RELEASE, 2.3.2.RELEASE, 2.3.3.RELEASE
Spring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to 2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0.16, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A maliciou…
- CVE-2019-3778MEDIUMCVSS 6.5EG 6.5fixed in 2.0.17.RELEASE, 2.1.4.RELEASE, 2.2.4.RELEASE or 2.3.5.RELEASE, by version range2019-03-07
vulnerable: 2.3.0.RELEASE, 2.3.1.RELEASE, 2.3.2.RELEASE, 2.3.3.RELEASE, 2.3.4.RELEASE
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization co…
- CVE-2022-22969MEDIUMCVSS 6.5EG 6.5fixed in 2.5.2.RELEASE or 2.4.2.RELEASE, by version range2022-04-21
vulnerable: 2.4.0.RELEASE, 2.4.1.RELEASE
<Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. …
Check whether org.springframework.security.oauth:spring-security-oauth2 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.springframework.security.oauth:spring-security-oauth2 CVEs against the assets you own.
Book a Demo →