Known vulnerabilities in Spring Security OAuth
Vendor:
Broadcom
Software:
Spring Security OAuth
Software CPE:
cpe:2.3:a:broadcom:spring_security_oauth:*:*:*:*:*:*:*:*
Website:
https://www.broadcom.com/
Total vulnerabilities:
6
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.5.2
2.5.1
2.5.0
2.4.2
2.4.1
2.4.0
2.3.8
2.3.7
2.2.6
2.1.6
2.0.19
1.0.10
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
2.3.6
2.0.18
2.0.17
2.1.5
2.1.4
2.2.5
2.2.4
2.3.5
2.3.4
2.2.3
2.1.3
2.0.16
2.3.2
2.3.1
2.3
2.2.1
2.2
2.1.1
2.1
2.0.14
2.0.13
2.0.12
2.0.11
2.0.10
2.0.9
2.0.8
2.0.7
2.0.6
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
2.0
2.0.15
2.1.2
2.2.2
2.3.3
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU62472 - Resource exhaustion CVE-2022-22969 |
CWE-400 | Medium | 2.5.2 | 21.04.2022 |
SB2022042129 SB2022042903 SB2022071933 and 2 more |
||
| #VU18660 - Insufficient Verification of Data Authenticity CVE-2019-11269 |
CWE-345 | Medium | 2.0.18, 2.1.5, 2.2.5, 2.3.6 | 03.06.2019 |
SB2019060307 SB2021012210 SB2021012214 and 6 more |
||
| #VU31150 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2019-3778 |
CWE-601 | Low | 2.3.5 | 07.03.2019 |
SB2019030715 SB2023042803 |
||
| #VU15466 - Permissions, Privileges, and Access Controls CVE-2018-15758 |
CWE-264 | Low | 2.0.16, 2.1.3, 2.2.3, 2.3.4 | 22.10.2018 |
SB2018102304 SB2019080913 SB2023042803 |
||
| #VU12919 - Improper input validation CVE-2018-1260 |
CWE-20 | High | - | 22.05.2018 |
SB2018051507 SB2023042803 |
||
| #VU38945 - Data Handling CVE-2016-4977 |
CWE-19 | High | - | 25.05.2017 |
SB2017052520 SB2023042803 |