← Vulnerability feed

Vulnerability record · CVE-2019-11269 · published 12 June 2019

CVE-2019-11269: Pivotal software spring security oauth open redirect vulnerability

Pivotal Software · Spring Security Oauth

Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint using the authorization code grant type, and specify a manipulated redirection URI via the redirect_uri parameter. This can cause the authorization server to redirect the resource owner user-agent to a URI under the control of the attacker with the leaked authorization code.

5.4 CVSS 3.1 Medium EPSS 8.9% · top 4.9% CWE-601 · Open redirect
5.4CVSS 3.1 base score, v2 5.8
8.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint using the authorization code grant type, and specify a manipulated redirection URI via the redirect_uri parameter. This can cause the authorization server to redirect the resource owner user-agent to a URI under the control of the attacker with the leaked authorization code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-11269 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-1260Pivotal software spring security oauth code injection vulnerabilitySpring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contai…EPSS 11%8.8CVE-2018-2706Oracle banking corporate lending vulnerabilityVulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported vers…EPSS 1.7%8.1CVE-2018-15758Pivotal software spring security oauth vulnerabilitySpring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to 2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0.16, and older unsupported ve…EPSS 2.2%8.1CVE-2018-3050Oracle banking corporate lending vulnerabilityVulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported vers…EPSS 2.0%8.1CVE-2018-2707Oracle banking corporate lending vulnerabilityVulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported vers…EPSS 1.6%7.1CVE-2020-2718Oracle banking corporate lending vulnerabilityVulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core). Supported versions that ar…EPSS 1.1%7.1CVE-2018-2746Oracle banking corporate lending vulnerabilityVulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported vers…EPSS 1.6%6.5CVE-2020-14894Oracle banking corporate lending vulnerabilityVulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core). Supported versions that ar…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2019-11269), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.