Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute URL is stored in the cookie and is used without validation as the post-login redirect target. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.7.24CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 5.8.0, < 5.8.26CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 6.3.0, < 6.3.17CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 6.4.0, < 6.4.17CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 6.5.0, < 6.5.10.2CPE matchmatch criteria | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.