| CVE-ID |
CVE-2018-15758
|
• CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information
|
| Description |
| Spring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to
2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0.16, and older
unsupported versions could be susceptible to a privilege escalation
under certain conditions. A malicious user or attacker can craft a
request to the approval endpoint that can modify the previously saved
authorization request and lead to a privilege escalation on the
subsequent approval. This scenario can happen if the application is
configured to use a custom approval endpoint that declares
AuthorizationRequest as a controller method argument. This
vulnerability exposes applications that meet all of the following
requirements: Act in the role of an Authorization Server (e.g.
@EnableAuthorizationServer) and use a custom Approval Endpoint that
declares AuthorizationRequest as a controller method argument. This
vulnerability does not expose applications that: Act in the role of an
Authorization Server and use the default Approval Endpoint, act in the
role of a Resource Server only (e.g. @EnableResourceServer), act in
the role of a Client only (e.g. @EnableOAuthClient).
|
| References |
|
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
|
|
|
| Assigning CNA |
| Dell EMC |
| Date Entry Created |
| 20180823 |
Disclaimer: The entry creation date may reflect when
the CVE ID was allocated or reserved, and does not
necessarily indicate when this vulnerability was
discovered, shared with the affected vendor, publicly
disclosed, or updated in CVE.
|
| Phase (Legacy) |
| Assigned (20180823) |
| Votes (Legacy) |
|
| Comments (Legacy) |
|
| Proposed (Legacy) |
| N/A |
|
This is an entry on the CVE List, which provides common identifiers for publicly known cybersecurity vulnerabilities. |
|
|
|
For More Information: cve@mitre.org
|