Loading HuntDB...

GHSA-32vj-v39g-jh23

GitHub Security Advisory

spring-security-oauth2-client vulnerable to Privilege Escalation

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a request initiated by the Client (via the browser) to the Authorization Server which can lead to a privilege escalation on the subsequent approval. This scenario can happen if the Authorization Server responds with an OAuth2 Access Token Response containing an empty scope list (per RFC 6749, Section 5.1) on the subsequent request to the token endpoint to obtain the access token.

Affected Packages

Maven org.springframework.security:spring-security-oauth2-client
Affected versions: 5.7.0 (fixed in 5.7.5)
Maven org.springframework.security:spring-security-oauth2-client
Affected versions: 0 (fixed in 5.6.9)

Related CVEs

Key Information

GHSA ID
GHSA-32vj-v39g-jh23
Published
November 1, 2022 12:00 PM
Last Modified
November 2, 2022 9:50 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.springframework.security:spring-security-oauth2-client
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 21, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.