CVE-2018-1260
CRITICALPivotal Software Spring Security Oauth < 2.0.14 - Code Injection
Title source: ruleDescription
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.
Exploits (1)
nomisec
WRITEUP
by shoucheng3 · poc
https://github.com/shoucheng3/SpringSource__spring-security-oauth_CVE-2018-1260_2-3-2-RELEASE
Scores
CVSS v3
9.8
EPSS
0.5033
EPSS Percentile
97.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (2)
org.springframework.security.oauth/spring-security-oauth2
2.3.0 - 2.3.3Maven
pivotal_software/spring_security_oauth
< 2.0.14
Published
May 11, 2018
Tracked Since
Feb 18, 2026