Spring Security Oauth
Vendor:
First CVE: May 25, 2017 · Active for 9 years
6
Total CVEs
More Total CVEs than 75% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 52% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spring Security Oauth over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 25, 2017
9 years ago
Most Recent CVE
Apr 21, 2022
1,559 days ago
CVE Severity & Scoring
Spring Security Oauth6 CVEs
50%
33%
17%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High1 (16.7%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low2 (33.3%)
High0 (0.0%)
None4 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4977HIGH When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spri | May 25, 2017 | 8.8 | 81 | NO | YES |
CVE-2019-3778MEDIUM Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to | Mar 7, 2019 | 6.5 | 41 | NO | YES |
CVE-2018-1260CRITICAL Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vuln | May 11, 2018 | 9.8 | 35 | NO | NO |
CVE-2019-11269MEDIUM Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an | Jun 12, 2019 | 5.4 | 34 | NO | YES |
CVE-2018-15758HIGH Spring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to 2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0.16, and older unsupported versions could be susceptible to | Oct 18, 2018 | 8.1 | 27 | NO | NO |
CVE-2022-22969MEDIUM <Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the | Apr 21, 2022 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
16.7% of CVEs· Bottom 1%
ExploitDB
2 CVEs
33.3% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Spring Security Oauth
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.9 | 1 | 8.8 | 79.2% | 0 | 1 |
| 2.0.8 | 1 | 8.8 | 79.2% | 0 | 1 |
| 2.0.7 | 1 | 8.8 | 79.2% | 0 | 1 |
| 2.0.6 | 1 | 8.8 | 79.2% | 0 | 1 |
| 2.0.5 | 1 | 8.8 | 79.2% | 0 | 1 |
| 2.0.4 | 1 | 8.8 | 79.2% | 0 | 1 |
| 2.0.3 | 1 | 8.8 | 79.2% | 0 | 1 |
| 2.0.2 | 1 | 8.8 | 79.2% | 0 | 1 |
| 2.0.1 | 1 | 8.8 | 79.2% | 0 | 1 |
| 2.0.0 | 1 | 8.8 | 79.2% | 0 | 1 |
| 1.0.5 | 1 | 8.8 | 79.2% | 0 | 1 |
| 1.0.4 | 1 | 8.8 | 79.2% | 0 | 1 |
| 1.0.3 | 1 | 8.8 | 79.2% | 0 | 1 |
| 1.0.2 | 1 | 8.8 | 79.2% | 0 | 1 |
| 1.0.1 | 1 | 8.8 | 79.2% | 0 | 1 |
| 1.0.0 | 1 | 8.8 | 79.2% | 0 | 1 |