Denial of service in Spring Security OAuth2
Moderate severity
GitHub Reviewed
Published
Apr 22, 2022
to the GitHub Advisory Database
•
Updated May 14, 2024
Package
Affected versions
>= 2.5.0.RELEASE, < 2.5.2.RELEASE
>= 2.4.0.RELEASE, < 2.4.2.RELEASE
Patched versions
2.5.2.RELEASE
2.4.2.RELEASE
Description
Published by the National Vulnerability Database
Apr 21, 2022
Published to the GitHub Advisory Database
Apr 22, 2022
Reviewed
Apr 26, 2022
Last updated
May 14, 2024
Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session. This vulnerability exposes OAuth 2.0 Client applications only.
References