Remote Code Execution (RCE) in Spring Security OAuth

HIGH | JULY 05, 2016 | CVE-2016-4977

Description

When processing authorization requests using the whitelabel views, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via the crafting of the value for response_type.

Affected Spring Products and Versions

Spring Security OAuth:

  • 2.0.0 - 2.0.9
  • 1.0.0 - 1.0.5

Mitigation

Users of affected versions should upgrade to the corresponding fixed version.
Fix versionAvailability
2.0.10OSS
  • Users of 1.0.x should not use whitelabel views for approval and error pages

Credit

This issue was found by David Vieira-Kurz (@secalert) and reported by Oliver Schoenherr on behalf of Immobilien Scout GmbH.

History

  • 2016-07-05: Initial vulnerability report published.
  • 2016-08-30: Update credit

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all