CVE-2021-22119
published 2021-06-29CVE-2021-22119: Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.00%
92.5th percentile
Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client Web and WebFlux application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session or multiple sessions.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | communications_cloud_native_core_policy | — | — |
| vmware | spring_security | — | — |
| vmware | spring_security | >= 5.2.0 < 5.2.11 | 5.2.11 |
| vmware | spring_security | >= 5.3.0 < 5.3.10 | 5.3.10 |
| vmware | spring_security | >= 5.4.0 < 5.4.7 | 5.4.7 |
| vmware | spring_security | >= 5.5.0 < 5.5.1 | 5.5.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Resource Exhaustion in Spring Security
ghsa·2021-07-02
CVE-2021-22119 [HIGH] CWE-400 Resource Exhaustion in Spring Security
Resource Exhaustion in Spring Security
Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client Web and WebFlux application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session or multiple sessions.
OSV
Resource Exhaustion in Spring Security
osv·2021-07-02
CVE-2021-22119 [HIGH] Resource Exhaustion in Spring Security
Resource Exhaustion in Spring Security
Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client Web and WebFlux application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session or multiple sessions.
Oracle
Oracle Oracle Communications Risk Matrix: NRF (Spring Security) — CVE-2021-22119
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2021-22119 [HIGH] Oracle Oracle Communications Risk Matrix: NRF (Spring Security) — CVE-2021-22119
Oracle Oracle Communications Risk Matrix: NRF (Spring Security) vulnerability
CVE: CVE-2021-22119
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Policy (Spring Security) — CVE-2021-22119
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2021-22119 [HIGH] Oracle Oracle Communications Risk Matrix: Policy (Spring Security) — CVE-2021-22119
Oracle Oracle Communications Risk Matrix: Policy (Spring Security) vulnerability
CVE: CVE-2021-22119
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Red Hat
spring-security: Denial-of-Service (DoS) attack via initiation of Authorization Request
vendor_redhat·2021-06-28·CVSS 7.5
CVE-2021-22119 [HIGH] CWE-400 spring-security: Denial-of-Service (DoS) attack via initiation of Authorization Request
spring-security: Denial-of-Service (DoS) attack via initiation of Authorization Request
Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client Web and WebFlux application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session or multiple sessions.
Package: spring-security-core (Red Hat Decision Manager 7) - Not affected
Package: spring-security-oauth2-client (Red Hat JBoss Fuse 6) - Out of support scope
Package: spring-security-core (Red Hat JBoss Fuse Ser
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread.html/r08a449010786e0bcffa4b5781b04fcb55d6eafa62cb79b8347680aad%40%3Cissues.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/r163b3e4e39803882f5be05ee8606b2b9812920e196daa2a82997ce14%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/r3868207b967f926819fe3aa8d33f1666429be589bb4a62104a49f4e3%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/r390783b3b1c59b978131ac08390bf77fbb3863270cbde59d5b0f5fde%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/r89aa1b48a827f5641310305214547f1d6b2101971a49b624737c497f%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/ra53677224fe4f04c2599abc88032076faa18dc84b329cdeba85d4cfc%40%3Cpluto-scm.portals.apache.org%3Ehttps://tanzu.vmware.com/security/cve-2021-22119https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://lists.apache.org/thread.html/r08a449010786e0bcffa4b5781b04fcb55d6eafa62cb79b8347680aad%40%3Cissues.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/r163b3e4e39803882f5be05ee8606b2b9812920e196daa2a82997ce14%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/r3868207b967f926819fe3aa8d33f1666429be589bb4a62104a49f4e3%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/r390783b3b1c59b978131ac08390bf77fbb3863270cbde59d5b0f5fde%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/r89aa1b48a827f5641310305214547f1d6b2101971a49b624737c497f%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/ra53677224fe4f04c2599abc88032076faa18dc84b329cdeba85d4cfc%40%3Cpluto-scm.portals.apache.org%3Ehttps://tanzu.vmware.com/security/cve-2021-22119https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-06-29
Published