Lucene search

K
githubGitHub Advisory DatabaseGHSA-X637-X8P3-5P22
HistoryMar 20, 2024 - 3:32 p.m.

Improper Authentication in Spring Authorization Server

2024-03-2015:32:28
CWE-287
GitHub Advisory Database
github.com
10
spring authorization server
improper authentication
pkce downgrade attack

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

7.2

Confidence

Low

EPSS

0

Percentile

9.0%

Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients.

Specifically, an application is vulnerable when a Confidential Clientย uses PKCE for the Authorization Code Grant.

An application is not vulnerable when a Public Clientย uses PKCE for the Authorization Code Grant.

Affected configurations

Vulners
Node
oauth2-server_projectoauth2-serverRange<1.2.3node.js
OR
oauth2-server_projectoauth2-serverRange<1.1.6node.js
VendorProductVersionCPE
oauth2-server_projectoauth2-server*cpe:2.3:a:oauth2-server_project:oauth2-server:*:*:*:*:*:node.js:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

7.2

Confidence

Low

EPSS

0

Percentile

9.0%