Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter.
An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability.
Spring Security:
| Fix version | Availability |
|---|---|
| 7.0.6 | OSS |
| 7.0.5.1 | Enterprise Support Only |
| 1.5.8 | OSS |
| 1.5.7.1 | Enterprise Support Only |
No further mitigation steps are necessary.
The issue was identified and responsibly reported by Jon Kjennbakken of Vipps MobilePay.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy