CVE-2018-1260
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 11.20% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- pivotal software/spring security oauth
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/bid/104158Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1809Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2939Third Party Advisory
- https://pivotal.io/security/cve-2018-1260Vendor Advisory
- http://www.securityfocus.com/bid/104158Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1809Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2939Third Party Advisory
- https://pivotal.io/security/cve-2018-1260Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.