在 Spring Authorization Server 1.5.0 至 1.5.7 版本中,授权端点对 参数的校验不足。攻击者可以构造一个包含无效 且 未经校验的请求,从而导致开放重定向(Open Redirect)到攻击者控制的网站。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| VMware | Spring Authorization Server | 1.5.0 ~ 1.5.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet