Spring Security 的 存在基于缓存的重放攻击漏洞。该组件内部用于存储 JWT ID( )声明的缓存具有严格的容量限制,攻击者可通过向服务器发送大量伪造请求,将合法的缓存条目驱逐出去,随后重放截获的有效 DPoP 证明(DPoP Proof),从而实现攻击。 受影响版本: Spring Security 7.1.0 Spring Security 7.0.0 至 7.0.6 Spring Security 6.5.0 至 6.5.11
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Spring | Spring Security | 7.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet