Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page presented to the end user.
Spring Authorization Server 1.5.0 - 1.5.8
Spring Authorization Server 1.4.0 - 1.4.11
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Broadcom Spring_Authorization_Server
cpe:2.3:a:broadcom:spring_authorization_server:*:*:*:*:*:*:*:*
|
1.4.0
|
1.4.12
|
|
Broadcom Spring_Authorization_Server
cpe:2.3:a:broadcom:spring_authorization_server:*:*:*:*:*:*:*:*
|
1.5.0
|
1.5.9
|