CVE-2016-4977

All FrameworksSpring FrameworkCWE-OtherCVE-2016-4977

CVE-2016-4977

State: PUBLISHED · Published: 2017-05-25 · Updated: 2024-08-06 · Assigner: dell
Description
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via the crafting of the value for response_type.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2016/4xxx/CVE-2016-4977.json