org.springframework.security.oauth:spring-security-oauth2
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.springframework.security.oauth:spring-security-oauth2page 1 of 1
- CVE-2016-4977HIGHCVSS 8.8EG 9.0✓ Fixed in 1.0.52017-05-25
vulnerable: 1.0.0.RELEASE, 1.0.1.RELEASE, 1.0.2.RELEASE, 1.0.3.RELEASE, 1.0.4.RELEASE
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote co…
- CVE-2018-1260CRITICALCVSS 9.8EG 9.82018-05-11
vulnerable: 1.0.0.RELEASE ... 1.0.5.RELEASE (6 versions)
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an author…
- CVE-2018-15758CRITICALCVSS 9.6EG 9.6✓ Fixed in 2.3.4.RELEASE2018-10-18
vulnerable: 2.3.0.RELEASE, 2.3.1.RELEASE, 2.3.2.RELEASE, 2.3.3.RELEASE
Spring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to 2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0.16, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A maliciou…
- CVE-2019-3778MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.3.5.RELEASE2019-03-07
vulnerable: 2.3.0.RELEASE, 2.3.1.RELEASE, 2.3.2.RELEASE, 2.3.3.RELEASE, 2.3.4.RELEASE
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization co…
- CVE-2022-22969MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.4.2.RELEASE2022-04-21
vulnerable: 2.4.0.RELEASE, 2.4.1.RELEASE
<Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. …
Check whether org.springframework.security.oauth:spring-security-oauth2 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.springframework.security.oauth:spring-security-oauth2 CVEs against the assets you own.
Start Free Scan →