Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-3778— Open Redirect in spring-security-oauth2

EPSS 14.85% · P95
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-3778

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Open Redirect in spring-security-oauth2
Source: NVD (National Vulnerability Database)
Vulnerability Description
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint using the authorization code grant type, and specify a manipulated redirection URI via the "redirect_uri" parameter. This can cause the authorization server to redirect the resource owner user-agent to a URI under the control of the attacker with the leaked authorization code. This vulnerability exposes applications that meet all of the following requirements: Act in the role of an Authorization Server (e.g. @EnableAuthorizationServer) and uses the DefaultRedirectResolver in the AuthorizationEndpoint. This vulnerability does not expose applications that: Act in the role of an Authorization Server and uses a different RedirectResolver implementation other than DefaultRedirectResolver, act in the role of a Resource Server only (e.g. @EnableResourceServer), act in the role of a Client only (e.g. @EnableOAuthClient).
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Pivotal Software Pivotal Spring Security OAuth 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Pivotal Software Pivotal Spring Security OAuth是美国Pivotal Software公司的一款为SpringWeb应用程序添加OAuth1和OAuth2功能提供支持的登录系统。 Pivotal Spring Security Oauth中存在开放重定向漏洞。攻击者可通过构建特制的URI并诱使用户点击该链接利用该漏洞将用户重定向到攻击者控制的网站,实施钓鱼攻击或获取敏感信息。以下版本受到影响:Pivotal Spring Security Oauth 2.3版本
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
SpringSpring Security OAuth 2.3 ~ 2.3.5.RELEASE -

II. Public POCs for CVE-2019-3778

#POC DescriptionSource LinkShenlong Link
1Spring Security OAuth 2.3 Open Redirection 分析复现篇https://github.com/BBB-man/CVE-2019-3778-Spring-Security-OAuth-2.3-Open-RedirectionPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-3778

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2019-3778

No comments yet


Leave a comment