org.springframework.security:spring-security-saml2-service-provider
Spring Security
Security Advisories for org.springframework.security:spring-security-saml2-service-provider in maven
Low
2 months ago
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads
maven
org.springframework.security:spring-security-saml2-service-provider
High
2 months ago
Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters
maven
org.springframework.security:spring-security-saml2-service-provider
High
2 months ago
Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository
maven
org.springframework.security:spring-security-saml2-service-provider
High
2 months ago
Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS)
maven
org.springframework.security:spring-security-saml2-service-provider
Potential
High
11 months ago
Spring Security annotation detection mechanism has authorization bypass
maven
org.springframework.security:spring-security-core
Potential
Critical
about 1 year ago
Spring Security authorization bypass for method security annotations on private methods
maven
org.springframework.security:spring-security-aspects
Potential
Moderate
over 1 year ago
Spring Security Vulnerable to Authorization Bypass via Security Annotations
maven
org.springframework.security:spring-security-core
Potential
High
over 1 year ago
Spring Security Does Not Enforce Password Length
maven
org.springframework.security:spring-security-crypto
Potential
Critical
almost 2 years ago
Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
maven
org.springframework.security:spring-security-web
Potential
High
over 2 years ago
Erroneous authentication pass in Spring Security
maven
org.springframework.security:spring-security-core
Potential
High
over 2 years ago
Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated
maven
org.springframework.security:spring-security-core
Potential
Moderate
over 2 years ago
Spring Security's spring-security.xsd file is world writable
maven
org.springframework.security:spring-security-config
Potential
Moderate
about 4 years ago
Integer overflow in BCrypt class in Spring Security
maven
org.springframework.security:spring-security-core
Potential
High
over 4 years ago
Improper Authentication in Spring Security
maven
org.springframework.security:spring-security-core
Potential
High
about 5 years ago
Resource Exhaustion in Spring Security
maven
org.springframework.security:spring-security-oauth2-client, org.springframework.security:spring-security-core
Potential
High
over 5 years ago
Privilege escalation in spring security
maven
org.springframework.security:spring-security-web
Potential
Critical
almost 6 years ago
Authorization Bypass in Spring Security
maven
org.springframework.security:spring-security-core
Potential
High
over 7 years ago
Spring Security vulnerable to Authorization Bypass
maven
org.springframework.security:spring-security-oauth2-jose, org.springframework.security:spring-security-core
Potential
High
almost 8 years ago
Spring Security and Spring Framework may not recognize certain paths that should be protected
maven
org.springframework.security:spring-security-core, org.springframework:spring-core