Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant.
An application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1035 | Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant. An application is not vulnerable when a Public Client uses PKCE for the Authorization Code Grant. |
Github GHSA |
GHSA-x637-x8p3-5p22 | Improper Authentication in Spring Authorization Server |
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2024-22258 |
|
Thu, 05 Dec 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-470 |
Wed, 20 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-12-05T20:31:25.882Z
Reserved: 2024-01-08T18:43:15.943Z
Link: CVE-2024-22258
Updated: 2024-08-01T22:43:33.663Z
Status : Deferred
Published: 2024-03-20T04:15:08.600
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-22258
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA