Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter.
An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability.
Spring Security:
Spring Authorization Server:
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 7.0.x | 7.0.6 | OSS |
| 1.5.x | 1.5.8 | OSS |
The issue was identified and responsibly reported by Jon Kjennbakken of Vipps MobilePay.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy