GHSA-c2cp-3xj9-97w9

Suggest an improvement
Source
https://github.com/advisories/GHSA-c2cp-3xj9-97w9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-c2cp-3xj9-97w9/GHSA-c2cp-3xj9-97w9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c2cp-3xj9-97w9
Aliases
Published
2022-04-22T00:00:33Z
Modified
2024-05-14T16:15:45.601106Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Denial of service in Spring Security OAuth2
Details

Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session. This vulnerability exposes OAuth 2.0 Client applications only.

Database specific
{
    "nvd_published_at": "2022-04-21T19:15:00Z",
    "cwe_ids": [
        "CWE-400"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2022-04-26T13:01:06Z"
}
References

Affected packages

Maven / org.springframework.security.oauth:spring-security-oauth2

Package

Name
org.springframework.security.oauth:spring-security-oauth2
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.security.oauth/spring-security-oauth2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.5.0.RELEASE
Fixed
2.5.2.RELEASE

Affected versions

2.*

2.5.0.RELEASE
2.5.1.RELEASE

Maven / org.springframework.security.oauth:spring-security-oauth2

Package

Name
org.springframework.security.oauth:spring-security-oauth2
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.security.oauth/spring-security-oauth2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.4.0.RELEASE
Fixed
2.4.2.RELEASE

Affected versions

2.*

2.4.0.RELEASE
2.4.1.RELEASE