Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20408
HistoryMay 31, 2019 - 5:11 a.m.

Open Redirection

2019-05-3105:11:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.003 Low

EPSS

Percentile

68.8%

spring-security-oauth2 is vulnerable to open redirection. A remote attacker is able to modify the redirect_uri parameter and redirect users to a malicious site to steal confidential information such as authorization code, username and password.