Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37813
HistoryNov 04, 2022 - 6:12 a.m.

Privilege Escalation

2022-11-0406:12:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
spring security oauth2 client
privilege escalation
gettokenresponse
access token response

0.003 Low

EPSS

Percentile

65.2%

Spring Security OAuth2 Client is vulnerable to Privilege Escalation. The vulnerability exists in the getTokenResponse function in multiple files due to the authorization server responding with an OAuth2 access token response containing an empty scope list which allows an attacker to modify requests initiated by clients.