Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a request initiated by the Client (via the browser) to the Authorization Server which can lead to a privilege escalation on the subsequent approval. This scenario can happen if the Authorization Server responds with an OAuth2 Access Token Response containing an empty scope list (per RFC 6749, Section 5.1) on the subsequent request to the token endpoint to obtain the access token.
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-beans-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-context-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-context-support-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-core-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-expression-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-instrument-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-jdbc-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-jms-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-orm-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-oxm-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-test-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-transaction-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-web-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" }, { "binary_name": "libspring-web-struts-java", "binary_version": "3.0.6.RELEASE-13ubuntu0.1~esm2" } ] }
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-beans-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-context-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-context-support-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-core-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-expression-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-instrument-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-jdbc-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-jms-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-orm-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-oxm-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-test-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-transaction-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-web-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "3.2.13-5ubuntu0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-beans-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-context-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-context-support-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-core-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-expression-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-instrument-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-jdbc-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-jms-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-messaging-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-orm-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-oxm-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-test-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-transaction-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-web-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "4.3.22-1~18.04.1~esm1" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "4.3.22-1~18.04.1~esm1" } ] }
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-beans-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-context-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-context-support-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-core-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-expression-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-instrument-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-jdbc-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-jms-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-messaging-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-orm-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-oxm-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-test-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-transaction-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-web-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "4.3.22-4ubuntu0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-beans-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-context-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-context-support-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-core-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-expression-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-instrument-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-jdbc-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-jms-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-messaging-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-orm-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-oxm-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-test-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-transaction-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-web-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "4.3.30-1" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "4.3.30-1" } ] }
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-beans-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-context-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-context-support-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-core-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-expression-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-instrument-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-jdbc-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-jms-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-messaging-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-orm-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-oxm-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-test-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-transaction-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-web-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "4.3.30-2" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "4.3.30-2" } ] }
{ "binaries": [ { "binary_name": "libspring-aop-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-beans-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-context-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-context-support-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-core-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-expression-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-instrument-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-jdbc-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-jms-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-messaging-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-orm-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-oxm-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-test-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-transaction-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-web-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-web-portlet-java", "binary_version": "4.3.30-2ubuntu1" }, { "binary_name": "libspring-web-servlet-java", "binary_version": "4.3.30-2ubuntu1" } ] }