GHSA-cvc6-q2cp-2xhw
Spring Security has Potential Security Misconfiguration when Using withIssuerLocation
Quick fix
GHSA-cvc6-q2cp-2xhw — org.springframework.security:spring-security-oauth2-jose: upgrade to the fixed version with the command below.
# pom.xml: bump <version>6.5.10</version> for org.springframework.security:spring-security-oauth2-joseDetails
Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling setJwtValidator. This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
Are you affected?
Enter the version of the package you're using.
Affected packages
6.3.0No fixed version published yet for org.springframework.security:spring-security-oauth2-jose (maven). Pin to a known-safe version or switch to an alternative.
6.4.0No fixed version published yet for org.springframework.security:spring-security-oauth2-jose (maven). Pin to a known-safe version or switch to an alternative.
6.5.0Fixed in: 6.5.10# pom.xml: bump <version>6.5.10</version> for org.springframework.security:spring-security-oauth2-jose7.0.0Fixed in: 7.0.5# pom.xml: bump <version>7.0.5</version> for org.springframework.security:spring-security-oauth2-jose