CVE-2021-22119
moderate-risk
Published 2021-06-29
Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client Web and WebFlux application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session or multiple sessions.
Do I need to act?
~
4.9% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (2)
References (18)
Vendor Advisory
https://tanzu.vmware.com/security/cve-2021-22119
Vendor Advisory
https://tanzu.vmware.com/security/cve-2021-22119
41
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
8/34 · Low
Exposure
7/34 · Low