PT-2026-82447 · Vmware · Spring Authorization Server
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Authorization Server versions 1.5.0 through 1.5.7
Description
The authorization endpoint performs insufficient validation of the
request uri parameter. An attacker can craft a request containing an invalid request uri paired with an unvalidated redirect uri, which can result in an open redirect to an attacker-controlled site.Recommendations
Update Spring Authorization Server to a version later than 1.5.7.
As a temporary mitigation, restrict or validate the
request uri and redirect uri parameters used in the authorization endpoint.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Authorization Server