Total vulnerabilities in the database
Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client Web and WebFlux application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session or multiple sessions.
Software | From | Fixed in |
---|---|---|
vmware / spring_security | 5.5.0 | 5.5.1 |
vmware / spring_security | 5.4.0 | 5.4.7 |
vmware / spring_security | 5.2.0 | 5.2.11 |
vmware / spring_security | 5.3.0 | 5.3.10 |
oracle / communications_cloud_native_core_policy | 1.14.0 | 1.14.0.x |
![]() |
5.5.0 | 5.5.1 |
![]() |
5.4.0 | 5.4.7 |
![]() |
5.3.0 | 5.3.10 |
![]() |
5.2.0 | 5.2.11 |
![]() |
5.5.0 | 5.5.1 |
![]() |
5.4.0 | 5.4.7 |
![]() |
5.3.0 | 5.3.10 |
![]() |
5.2.0 | 5.2.11 |