Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36352
HistoryJul 14, 2022 - 7:01 a.m.

Denial Of Service (DoS)

2022-07-1407:01:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
26
denial of service
spring security oauth2 client
resource exhaustion
authorization code grant
single session
multiple sessions

0.006 Low

EPSS

Percentile

77.6%

org.springframework.security:spring-security-oauth2-client is vulnerable to denial of service (DoS) attacks. An attacker is able to cause resource exhaustion via sending multiple requests initiating the authorization request for the authorization code grant using a single session or multiple sessions, resulting in denial of service conditions.

References