An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HVMware Spring Security
APPVmware5.7.0 – 5.7.24 (excl.)5.8.0 – 5.8.26 (excl.)6.3.0 – 6.3.17 (excl.)6.4.0 – 6.4.17 (excl.)6.5.0 – 6.5.10.2 (excl.)7.0.0 – 7.0.5.1 (excl.)
Related vulnerabilities
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrat...
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client R...
VMware Spring Security — brak zapisu nagłówków HTTP odpowiedzi
Spring Security WebFlux: ominięcie zabezpieczeń przez wzorzec "**"
Spring Security: pominięcie reguł autoryzacji przez forward/include dispatcher