PT-2021-3475 · Spring · Spring Security

Published

2021-06-29

·

Updated

2022-07-25

·

CVE-2021-22119

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Spring Security versions 5.2.x prior to 5.2.11 Spring Security versions 5.3.x prior to 5.3.10 Spring Security versions 5.4.x prior to 5.4.7 Spring Security versions 5.5.x prior to 5.5.1
Description The issue is related to an uncontrolled resource consumption in the Spring Security framework, which can be exploited by a remote attacker to cause a denial-of-service (DoS) via requests that initiate an authorization request for the authorization code grant in an OAuth 2.0 Client Web and WebFlux application. This can lead to the exhaustion of system resources using a single session or multiple sessions.
Recommendations For Spring Security version 5.2.x prior to 5.2.11, update to version 5.2.11 or later. For Spring Security version 5.3.x prior to 5.3.10, update to version 5.3.10 or later. For Spring Security version 5.4.x prior to 5.4.7, update to version 5.4.7 or later. For Spring Security version 5.5.x prior to 5.5.1, update to version 5.5.1 or later.

Fix

Incorrect Authorization

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03390
CVE-2021-22119
GHSA-W9JG-GVGR-354M

Affected Products

Spring Security