spring-security-saml2-service-provider is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
75
High Risk
An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters.
You are affected if you are using a version that falls within the vulnerable range.
spring-security-saml2-service-provider is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.1 - 5.7.23, 5.8.0 - 5.8.25, 6.0.0 - 6.3.16, 6.4.0 - 6.4.16, 6.5.0 - 6.5.10 and 7.0.0 - 7.0.5.
Upgrade the org.springframework.security:spring-security-saml2-service-provider library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant