Pivotal Spring Security OAuth是美国Pivotal Software公司的一个项目,该项目为Spring Web应用程序添加OAuth1和OAuth2功能提供支持。 Pivotal Spring Security OAuth中存在远程代码执行漏洞。远程攻击者可通过向授权端点发送特制的授权请求利用该漏洞执行代码。以下产品和版本受到影响:Spring Security OAuth 2.3.3之前的2.3版本,2.2.2之前的2.2版本,2.1.2之前的2.版本,2.0.15之前的2
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Pivotal | Spring Security OAuth | 2.3 prior to 2.3.3; 2.2 prior to 2.2.2; 2.1 prior to 2.1.2; 2.0 prior to 2.0.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/shoucheng3/SpringSource__spring-security-oauth_CVE-2018-1260_2-3-2-RELEASE | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-1257 | Pivotal Spring Framework 输入验证错误漏洞 | |
| CVE-2018-1258 | Vmware Spring Framework和VMware Spring Security 授权问题漏洞 | |
| CVE-2018-1259 | Pivotal Spring Data Commons 安全漏洞 | |
| CVE-2018-1261 | Pivotal Spring-integration-zip 安全漏洞 | |
| CVE-2018-1278 | Pivotal Application Service Apps Manager 安全漏洞 | |
| CVE-2018-1280 | Pivotal Greenplum Command Center SQL注入漏洞 |
No comments yet