pivotalsoftware spring-security-oauth CVE-2018-1260 is a vulnerability in Pivotal Software Spring Security Oauth
Published on May 11, 2018

Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.

Vendor Advisory Vendor Advisory NVD


Products Associated with CVE-2018-1260

Want to know whenever a new CVE is published for Pivotal Software Spring Security Oauth? stack.watch will email you.

 

Affected Versions

Pivotal Spring Security OAuth Version 2.3 prior to 2.3.3; 2.2 prior to 2.2.2; 2.1 prior to 2.1.2; 2.0 prior to 2.0.15 is affected by CVE-2018-1260

Exploit Probability

EPSS
61.67%
Percentile
98.30%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.