Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.springframework.security.oauth/spring-security-oauth2
  4. ›
  5. CVE-2018-1260

CVE-2018-1260: Code Injection

May 11, 2018 (updated March 13, 2019)

Spring Security OAuth contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.

References

  • www.securityfocus.com/bid/104158
  • nvd.nist.gov/vuln/detail/CVE-2018-1260
  • pivotal.io/security/cve-2018-1260

Code Behaviors & Features

Detect and mitigate CVE-2018-1260 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 2.0.14.RELEASE, all versions starting from 2.1.RELEASE up to 2.1.1.RELEASE, all versions starting from 2.2.RELEASE up to 2.2.1.RELEASE, all versions starting from 2.3.RELEASE up to 2.3.2.RELEASE

Fixed versions

  • 2.0.15.RELEASE
  • 2.1.2.RELEASE
  • 2.2.2.RELEASE
  • 2.3.3.RELEASE

Solution

Upgrade to versions 2.0.15.RELEASE, 2.1.2.RELEASE, 2.2.2.RELEASE, 2.3.3.RELEASE or above.

Impact 9.8 CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Source file

maven/org.springframework.security.oauth/spring-security-oauth2/CVE-2018-1260.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:12 +0000.