Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page presented to the end user. Spring Authorization Server 1.5.0 - 1.5.8 Spring Authorization Server 1.4.0 - 1.4.11
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:NBroadcom Spring Authorization Server
APPBroadcom1.4.0 – 1.4.12 (bez)1.5.0 – 1.5.9 (bez)
Powiązane podatności
Authentication Bypass w Spring Security Spring Authorization Server
In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficie...
Punkt autoryzacyjny Spring Security Authorization Server wykonuje niewystarczającą walidację parametru request...
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
RCE w Spring Data Commons — podatność property bindera