Spring Security OAuth < 2.0.14, 2.3.0-2.3.2 - Remote Code Execution via Authorization Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-1260. PoCs published by shoucheng3.
AI-analyzed exploit summary This repository contains documentation and sample code for Spring Security OAuth, including details about CVE-2018-1260. It provides setup instructions, sample applications, and integration tests but does not include an actual exploit PoC.
Description
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.
Exploits (1)
This repository contains documentation and sample code for Spring Security OAuth, including details about CVE-2018-1260. It provides setup instructions, sample applications, and integration tests but does not include an actual exploit PoC.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H