Vulnerability record · CVE-2016-4977 · published 25 May 2017
CVE-2016-4977: Spring Security OAuth whitelabel views SpEL injection enables RCE
Pivotal · Spring Security Oauth
Spring Security OAuth versions 2.0.0-2.0.9 and 1.0.0-1.0.5 execute the response_type parameter as Spring Expression Language (SpEL) when processing authorization requests through the whitelabel views. Because the value is evaluated as an expression rather than treated as data, an attacker can inject SpEL that runs arbitrary code on the server. This is a high-severity remote code execution flaw in a widely used authorization component.
Description
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via the crafting of the value for response_type.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with a CVSS of 8.8 and an EPSS above the 99th percentile, though exploitation requires a low-privilege authenticated position.
What it is
Spring Security OAuth versions 2.0.0-2.0.9 and 1.0.0-1.0.5 execute the response_type parameter as Spring Expression Language (SpEL) when processing authorization requests through the whitelabel views. Because the value is evaluated as an expression rather than treated as data, an attacker can inject SpEL that runs arbitrary code on the server. This is a high-severity remote code execution flaw in a widely used authorization component.
Impact
An attacker who can reach the OAuth authorization endpoint gains remote code execution with the privileges of the application server, allowing full compromise of the host and any data or credentials it can reach.
Attack surface
Reached over the network via the OAuth authorization request, specifically the response_type parameter handled by the whitelabel views. The CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates a low-privilege authenticated attacker is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high (0.79176 probability, 99.579th percentile), indicating substantial observed or expected exploitation activity.
What to do
- Upgrade Spring Security OAuth to a version outside the affected ranges (2.0.0-2.0.9 and 1.0.0-1.0.5) as directed by the vendor advisory.
- If immediate upgrade is not possible, disable or replace the whitelabel authorization views so the response_type value is not evaluated as SpEL.
- Restrict network access to OAuth authorization endpoints to trusted clients and networks.
- Review application logs and server behavior for unexpected expression evaluation or command execution around authorization requests.
- Monitor the vendor advisory and apply any follow-up patches or configuration guidance.
Detection
- Inspect HTTP requests to OAuth authorization endpoints for response_type values containing SpEL syntax such as T(), #{}, or Runtime/ProcessBuilder references.
- Alert on anomalous child processes or command execution spawned by the Java application server hosting Spring Security OAuth.
- Correlate authorization endpoint access with subsequent outbound connections or file writes from the application host.
- Review application and WAF logs for encoded or obfuscated response_type parameters that deviate from expected OAuth grant type values.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-4977 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-4977), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.