CyberRota Analysis
AI-GeneratedVersions 1.5.0 to 1.5.7 of Spring Authorization Server are vulnerable due to inadequate validation of the request_uri parameter at the authorization endpoint. This flaw allows attackers to exploit the system by crafting requests that redirect users to malicious sites, potentially leading to phishing attacks or other security breaches. Organizations using these versions should prioritize patching to mitigate the risk of open redirects and protect user data.
Original NVD Description
In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an attacker-controlled site.
Related CVEs
Other vulnerabilities affecting the same vendor(s)