First published: Thu May 30 2019(Updated: )
Spring Security OAuth could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using redirect_uri parameter in a specially-crafted URL to redirect a victim to arbitrary Web sites.
Credit: security@pivotal.io security@pivotal.io
Affected Software | Affected Version | How to fix |
---|---|---|
IBM GDE | <=3.0.0.2 | |
Pivotal Software Spring Security Oauth | >=2.0.0<2.0.18 | |
Pivotal Software Spring Security Oauth | >=2.1.0<2.1.5 | |
Pivotal Software Spring Security Oauth | >=2.2.0<2.2.5 | |
Pivotal Software Spring Security Oauth | >=2.3.0<2.3.6 | |
Oracle Banking Corporate Lending | =14.1.0 | |
Oracle Banking Corporate Lending | =14.3.0 | |
Oracle Banking Corporate Lending | =14.4.0 | |
maven/org.springframework.security.oauth:spring-security-oauth | >=2.3.0.RELEASE<2.3.6.RELEASE | 2.3.6.RELEASE |
maven/org.springframework.security.oauth:spring-security-oauth | >=2.2.0.RELEASE<2.2.5.RELEASE | 2.2.5.RELEASE |
maven/org.springframework.security.oauth:spring-security-oauth | >=2.1.0.RELEASE<2.1.5.RELEASE | 2.1.5.RELEASE |
maven/org.springframework.security.oauth:spring-security-oauth | >=2.0.0.RELEASE<2.0.18.RELEASE | 2.0.18.RELEASE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security vulnerability is CVE-2019-11269.
CVE-2019-11269 has a severity score of 7.4, which is considered high.
The affected software for CVE-2019-11269 includes Spring Security OAuth versions 2.0 to 2.0.18, 2.1 to 2.1.5, 2.2 to 2.2.5, and 2.3 to 2.3.6, as well as older unsupported versions.
A remote attacker can exploit CVE-2019-11269 through an open redirector attack, which can leak an authorization code and potentially lead to phishing attacks.
Yes, you can find more information about CVE-2019-11269 at the following references: [Reference 1](http://packetstormsecurity.com/files/153299/Spring-Security-OAuth-2.3-Open-Redirection.html), [Reference 2](https://pivotal.io/security/cve-2019-11269), and [Reference 3](https://www.oracle.com/security-alerts/cpujan2021.html).