CVE-2021-22119: Input Validation
Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client Web and WebFlux application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session or multiple sessions.
Other sources
VMware Tanzu Spring Security is vulnerable to a denial of service, caused by improper input validation. By sending specially-crafted requests to initiate the Authorization Request for the Authorization Code Grant, a remote attacker could exploit this vulnerability to exhaust available system resources.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-22119?
CVE-2021-22119 is a vulnerability in Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10, and 5.2.x prior to 5.2.11 that allows for a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client Web and WebFlux application.
How severe is CVE-2021-22119?
CVE-2021-22119 is considered to be a high severity vulnerability with a severity value of 7.
Which software versions are affected by CVE-2021-22119?
Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10, and 5.2.x prior to 5.2.11 are affected by CVE-2021-22119.
How can I fix CVE-2021-22119?
To fix CVE-2021-22119, update your Spring Security version to 5.5.1, 5.4.7, 5.3.10, or 5.2.11 depending on the version you are currently using.
Where can I find more information about CVE-2021-22119?
You can find more information about CVE-2021-22119 at the following references: [CVE-2021-22119](https://www.cve.org/CVERecord?id=CVE-2021-22119), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-22119), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1977064), [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2022:5532).