Spring Authorization Server
- >= 7.0.0, <= 7.0.4
- >= 1.5.0, <= 1.5.6
- >= 1.4.0, <= 1.4.9
- >= 1.3.0, <= 1.3.10
A vulnerability in Spring Security Authorization Server's Dynamic Client Registration endpoints allows for authentication bypass by primary weakness. This issue arises from insufficient validation of client metadata fields when dynamic registration is enabled. An attacker with a valid Initial Access Token could register a malicious client with crafted metadata, potentially leading to Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF). The vulnerability affects Spring Authorization Server versions 7.0.0 through 7.0.4, 1.5.0 through 1.5.6, 1.4.0 through 1.4.9, and 1.3.0 through 1.3.10.
Exploitation of this vulnerability could result in unauthorized authentication, allowing an attacker to bypass authentication mechanisms and potentially gain elevated privileges within the application. Additionally, depending on the crafted metadata and the Authorization Server's configuration, this vulnerability could lead to Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF).
Users should upgrade to Spring Authorization Server versions 7.0.5, 1.5.7, 1.4.10 (Enterprise Support Only), or 1.3.11 (Enterprise Support Only).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.