Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Security OAuth, versions 2.3 prior to 2.3.3 and 2.2 prior to 2.2.2 and 2.1 prior to 2.1.2 and 2.0 prior to 2.0.15 and older unsupported versions, contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to a remote code execution when the resource owner is forwarded to the approval endpoint.
This vulnerability exposes applications that meet all of the following requirements:
This vulnerability does not expose applications that:
Spring Security OAuth:
| Fix version | Availability |
|---|---|
| 2.3.3 | OSS |
| 2.2.2 | OSS |
| 2.1.2 | OSS |
| 2.0.15 | OSS |
No further mitigation steps are necessary.
This issue was identified and responsibly reported by Philippe Arteau from GoSecure.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy