VDB
Sign up
MEDIUM5.3

GHSA-cvc6-q2cp-2xhw

Spring Security has Potential Security Misconfiguration when Using withIssuerLocation

Quick fix

GHSA-cvc6-q2cp-2xhw — org.springframework.security:spring-security-oauth2-jose: upgrade to the fixed version with the command below.

# pom.xml: bump <version>6.5.10</version> for org.springframework.security:spring-security-oauth2-jose

Details

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling setJwtValidator. This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.springframework.security:spring-security-oauth2-jose
Introduced in: 6.3.0

No fixed version published yet for org.springframework.security:spring-security-oauth2-jose (maven). Pin to a known-safe version or switch to an alternative.

Maven/org.springframework.security:spring-security-oauth2-jose
Introduced in: 6.4.0

No fixed version published yet for org.springframework.security:spring-security-oauth2-jose (maven). Pin to a known-safe version or switch to an alternative.

Maven/org.springframework.security:spring-security-oauth2-jose
Introduced in: 6.5.0Fixed in: 6.5.10
Fix# pom.xml: bump <version>6.5.10</version> for org.springframework.security:spring-security-oauth2-jose
Maven/org.springframework.security:spring-security-oauth2-jose
Introduced in: 7.0.0Fixed in: 7.0.5
Fix# pom.xml: bump <version>7.0.5</version> for org.springframework.security:spring-security-oauth2-jose

References