Impact
An authentication bypass has been identified in the OAuth2 implementation of Spotfire. The flaw enables a public OAuth client to obtain a valid authorization code and access token without performing the PKCE code verification that should be required for non‑confidential clients. This weakness removes an essential safeguard and provides a route for attackers to acquire authorized access to Spotfire data and services without providing a client secret or the required code challenge. The impact is that compromised data confidentiality, integrity, and availability can be affected depending on the permissions granted to the client.
Affected Systems
Spotfire Enterprise, Spotfire Enterprise with External Consumers, and Spotfire on Kubernetes are impacted. All versions from Spotfire Enterprise 14.0.12 up through 14.8.0, Spotfire Enterprise with External Consumers 14.0.12 through 14.8.0, and Spotfire on Kubernetes releases 4.2.0, 5.x, and 6.x contain the flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is below 1 %, suggesting that exploitation is currently not widespread. It is not listed in the CISA KEV catalog. The attack likely involves initiating an OAuth flow from a public client, capturing the authorization code, and using it to request an access token without the expected PKCE validation. If successful, the attacker can obtain tokens with the client’s scopes and access protected Spotfire resources. No specific prerequisites are noted, so a user with the ability to launch the OAuth flow on a public client can potentially exploit the bypass.
OpenCVE Enrichment