在 Spring Security OAuth2 授权服务器模块 7.0.0 到 7.0.4 版本中,当显式启用了动态客户端注册(Dynamic Client Registration)时,注册端点对注册客户端提供的某些客户端元数据字段执行了不充分的验证。拥有有效初始访问令牌(Initial Access Token)的攻击者可以注册一个包含经过构造的元数据的恶意客户端。根据服务器配置以及元数据后续如何被渲染或使用,这可能导致存储型跨站脚本攻击(Stored XSS)、权限提升或服务器端请求伪造(SSRF)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| VMware by Broadcom | Spring Security (OAuth2 Authorization Server module) | 7.0.0 ~ 7.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet