{"id":"GHSA-x637-x8p3-5p22","summary":"Improper Authentication in Spring Authorization Server","details":"Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients.\n\nSpecifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant.\n\nAn application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.\n\n","aliases":["CVE-2024-22258"],"modified":"2024-12-05T22:24:50.094223Z","published":"2024-03-20T15:32:28Z","database_specific":{"cwe_ids":["CWE-287","CWE-470"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-03-20T17:09:02Z","nvd_published_at":"2024-03-20T04:15:08Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-22258"},{"type":"WEB","url":"https://github.com/spring-projects/spring-authorization-server/commit/a7035d22bd2de6c24e7125623d38fb83d8f659a9"},{"type":"WEB","url":"https://spring.io/security/cve-2024-22258"},{"type":"PACKAGE","url":"github.com/spring-projects/spring-authorization-server"}],"affected":[{"package":{"name":"org.springframework.security:spring-security-oauth2-authorization-server","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-oauth2-authorization-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.6"}]}],"versions":["0.2.0","0.2.1","0.2.2","0.2.3","0.3.0","0.3.1","0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5","1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-x637-x8p3-5p22/GHSA-x637-x8p3-5p22.json"}},{"package":{"name":"org.springframework.security:spring-security-oauth2-authorization-server","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-oauth2-authorization-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2.0"},{"fixed":"1.2.3"}]}],"versions":["1.2.0","1.2.1","1.2.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-x637-x8p3-5p22/GHSA-x637-x8p3-5p22.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}