5.8
CVSSv2

CVE-2019-11269

Published: 12/06/2019 Updated: 30/01/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Spring Security OAuth versions 2.3 before 2.3.6, 2.2 before 2.2.5, 2.1 before 2.1.5, and 2.0 before 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint using the authorization code grant type, and specify a manipulated redirection URI via the redirect_uri parameter. This can cause the authorization server to redirect the resource owner user-agent to a URI under the control of the attacker with the leaked authorization code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal software spring security oauth

oracle banking corporate lending 14.1.0

oracle banking corporate lending 14.3.0

oracle banking corporate lending 14.4.0

Exploits

# Exploit Title: Open Redirector in spring-security-oauth2 # Date: 17 June 2019 # Exploit Author: Riemann # Vendor Homepage: springio/projects/spring-security-oauth # Software Link: springio # Version: Spring Security OAuth versions 23 prior to 236 -orgspringframeworksecurityoauth:spring-security-oauth2:233RELEASE # Teste ...
Spring Security OAuth versions 23 prior to 236 suffer from open redirection vulnerabilities ...

Github Repositories

Spring Security OAuth 2.3 Open Redirection 分析复现篇

CVE-2019-3778-Spring-Security-OAuth-23-Open-Redirection Spring Security OAuth 23 Open Redirection 分析复现篇 Exploit Title: Open Redirector in spring-security-oauth2 Date: 17 June 2019 Exploit Author: Riemann Vendor Homepage: springio/projects/spring-security-oauth Software Link: springio Version: Spring Security OAuth versions 23 prior to 236 -org