OSV 1.4.0 · unreviewed · 修改于 2026-08-28 05:31
发布时间
2026-08-28 05:31
GitHub 审查时间
—
NVD 发布时间
2026-08-28 04:17
源文件
advisories/unreviewed/2026/08/GHSA-5pc3-v4c3-6pv4/GHSA-5pc3-v4c3-6pv4.json
Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page presented to the end user. Spring Authorization Server 1.5.0 - 1.5.8 Spring Authorization Server 1.4.0 - 1.4.11
该公告没有提供结构化的受影响软件包信息。