{"id":"GHSA-rrpm-pj7p-7j9q","summary":"Spring Security OAuth vulnerable to remote code execution (RCE)","details":"Spring Security OAuth versions prior to 2.3.3, prior to 2.2.2, prior to 2.1.2, and prior to 2.0.15 contain a remote code execution vulnerability. An attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint. ","aliases":["CVE-2018-1260"],"modified":"2024-05-14T18:02:08.279094Z","published":"2018-10-18T18:05:34Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:55:47Z","nvd_published_at":null,"cwe_ids":["CWE-94"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1260"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:1809"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:2939"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rrpm-pj7p-7j9q"},{"type":"PACKAGE","url":"https://github.com/spring-attic/spring-security-oauth"},{"type":"WEB","url":"https://pivotal.io/security/cve-2018-1260"},{"type":"WEB","url":"https://web.archive.org/web/20200227123539/http://www.securityfocus.com/bid/104158"}],"affected":[{"package":{"name":"org.springframework.security.oauth:spring-security-oauth2","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security.oauth/spring-security-oauth2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3.0"},{"fixed":"2.3.3"}]}],"versions":["2.3.0.RELEASE","2.3.1.RELEASE","2.3.2.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-rrpm-pj7p-7j9q/GHSA-rrpm-pj7p-7j9q.json"}},{"package":{"name":"org.springframework.security.oauth:spring-security-oauth2","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security.oauth/spring-security-oauth2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.2"}]}],"versions":["2.2.0.RELEASE","2.2.1.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-rrpm-pj7p-7j9q/GHSA-rrpm-pj7p-7j9q.json"}},{"package":{"name":"org.springframework.security.oauth:spring-security-oauth2","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security.oauth/spring-security-oauth2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.2"}]}],"versions":["2.1.0.RELEASE","2.1.1.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-rrpm-pj7p-7j9q/GHSA-rrpm-pj7p-7j9q.json"}},{"package":{"name":"org.springframework.security.oauth:spring-security-oauth2","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security.oauth/spring-security-oauth2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.15"}]}],"versions":["2.0.0.RELEASE","2.0.1.RELEASE","2.0.10.RELEASE","2.0.11.RELEASE","2.0.12.RELEASE","2.0.13.RELEASE","2.0.14.RELEASE","2.0.2.RELEASE","2.0.3.RELEASE","2.0.4.RELEASE","2.0.5.RELEASE","2.0.6.RELEASE","2.0.7.RELEASE","2.0.8.RELEASE","2.0.9.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-rrpm-pj7p-7j9q/GHSA-rrpm-pj7p-7j9q.json"}},{"package":{"name":"org.springframework.security.oauth:spring-security-oauth2","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security.oauth/spring-security-oauth2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"last_affected":"1.0.5"}]}],"versions":["1.0.0.RELEASE","1.0.1.RELEASE","1.0.2.RELEASE","1.0.3.RELEASE","1.0.4.RELEASE","1.0.5.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-rrpm-pj7p-7j9q/GHSA-rrpm-pj7p-7j9q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}