GHSA-32vj-v39g-jh23
HIGHCVE-2022-31690Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a request initiated by the Client (via the browser) to the Authorization Server which can lead to a privilege escalation on the subsequent approval. This scenario can happen if the Autho
- Affected
- >= 5.7.0, < 5.7.5, < 5.6.9
- Fixed in
- 5.7.5
- Weakness
- CWE-269
- Published
- 2022-11-01
- Source
- github