CVE-2019-11269 is an open redirect vulnerability affecting Spring Security OAuth versions 2.3.6 and earlier, 2.2.5 and earlier, 2.1.5 and earlier, and 2.0.18 and earlier, as well as Oracle and Pivotal Banking Corporate Lending. An attacker can craft a malicious authorization request to redirect a user to an attacker-controlled URI, potentially leaking an authorization code. This vulnerability has a CVSS score of 5.4 (Medium) due to its network-based attack vector, low attack complexity, and potential for partial confidentiality and integrity impact. While there is no evidence of active exploitation, an ExploitDB entry (EDB-47000) exists, and it has a FAUCET Risk Score of 84/100, indicating a higher potential for exploitation despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.0.18CPE matchmatch criteria | cpe:2.3:a:pivotal_software:spring_security_oauth:*:*:*:*:*:*:*:* | ||
>= 2.1.0, < 2.1.5CPE matchmatch criteria | cpe:2.3:a:pivotal_software:spring_security_oauth:*:*:*:*:*:*:*:* | ||
>= 2.2.0, < 2.2.5CPE matchmatch criteria | cpe:2.3:a:pivotal_software:spring_security_oauth:*:*:*:*:*:*:*:* | ||
>= 2.3.0, < 2.3.6CPE matchmatch criteria | cpe:2.3:a:pivotal_software:spring_security_oauth:*:*:*:*:*:*:*:* | ||
14.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:banking_corporate_lending:14.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.