Security Advisory

CVE-2021-22119

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-06-29 16:15:05
Last updated 2024-08-03 18:30:23
Assigner vmware
CVSS score not scored
State PUBLISHED

Description

Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client Web and WebFlux application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session or multiple sessions.