Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Authorization Server is susceptible to a PKCE Downgrade Attack for Confidential Clients.
Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant.
An application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.
Spring Authorization Server:
| Fix version | Availability |
|---|---|
| 1.2.3 | OSS |
| 1.1.6 | OSS |
| 1.0.6 | Enterprise Support Only |
No further mitigation steps are necessary.
This issue was identified and responsibly reported by Pieter Philippaerts ([email protected]).
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy