In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an attacker-controlled site.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NBroadcom Spring Authorization Server
APPBroadcom1.5.0 – 1.5.7.1 (bez)
Powiązane podatności
Authentication Bypass w Spring Security Spring Authorization Server
Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding...
Punkt autoryzacyjny Spring Security Authorization Server wykonuje niewystarczającą walidację parametru request...
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
RCE w Spring Data Commons — podatność property bindera