Impact
The vulnerability is an insufficient validation of the request_uri parameter in Spring Authorization Server versions 1.5.0 through 1.5.7. An attacker can submit a crafted request that contains an invalid request_uri together with an unvalidated redirect_uri. The resulting open redirect can send users to attacker‐controlled sites, enabling phishing or other social engineering attacks. The weakness is a classic Redirect Vulnerability (CWE‑601).
Affected Systems
The issue affects VMware’s Spring Authorization Server. All releases from 1.5.0 up to and including 1.5.7 are impacted; the fix is released in 1.5.8 for OSS and 1.5.7.1 for Enterprise customers.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. No EPSS score is available, so the current probability of exploitation is uncertain, but the presence of this flaw makes it likely that attackers can abuse the redirect functionality in contexts where user authentication flows are used. The vulnerability is not listed in the CISA KEV catalog, yet the ability to redirect users to malicious sites is a common attack technique that can be leveraged in phishing campaigns.
OpenCVE Enrichment