spring-security-core is vulnerable to Open Redirect
61
Medium Risk
Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability.
You are affected if you are using a version that falls within the vulnerable range.
spring-security-core is vulnerable to Open Redirect in versions 7.0.0 - 7.0.5.
Upgrade the org.springframework.security:spring-security-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant