QID 981308
QID 981308: Java (maven) Security Update for org.hswebframework.web:hsweb-commons (GHSA-4rm3-4mq4-mfwr)
A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4rm3-4mq4-mfwr for updates pertaining to this vulnerability.
Vendor References
- GHSA-4rm3-4mq4-mfwr -
github.com/advisories/GHSA-4rm3-4mq4-mfwr
CVEs related to QID 981308
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4rm3-4mq4-mfwr | org.hswebframework.web:hsweb-commons |
|