CVE-2019-3778 is an open redirect vulnerability in Spring Security OAuth versions prior to 2.3.5, 2.2.4, 2.1.4, and 2.0.17, affecting applications acting as an Authorization Server using DefaultRedirectResolver. An attacker can craft a malicious request to leak an authorization code by manipulating the redirect_uri parameter. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring no privileges or user interaction, and potentially leading to low confidentiality and integrity impact. Its FAUCET Risk Score is 93/100. While not listed on the KEV catalog or Hot List, an ExploitDB entry (EDB-47000) exists, indicating public exploit code availability. There is no evidence of active exploitation, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.0.17CPE matchmatch criteria | cpe:2.3:a:pivotal_software:spring_security_oauth:*:*:*:*:*:*:*:* | ||
>= 2.1.0, < 2.1.4CPE matchmatch criteria | cpe:2.3:a:pivotal_software:spring_security_oauth:*:*:*:*:*:*:*:* | ||
>= 2.2.0, < 2.2.4CPE matchmatch criteria | cpe:2.3:a:pivotal_software:spring_security_oauth:*:*:*:*:*:*:*:* | ||
>= 2.3.0, < 2.3.5CPE matchmatch criteria | cpe:2.3:a:pivotal_software:spring_security_oauth:*:*:*:*:*:*:*:* | ||
14.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:banking_corporate_lending:14.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.