CyberRota Analysis
AI-GeneratedThe Spring Security Authorization Server's default consent page is vulnerable due to the lack of HTML entity encoding for user-controlled values, potentially allowing for cross-site scripting (XSS) attacks. This vulnerability affects versions 7.0.0 to 7.0.6 and 7.1.0, posing a significant risk to applications utilizing these versions. Organizations using the affected Spring Security versions should prioritize remediation to protect against potential exploitation.
Original NVD Description
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6
Related CVEs
Other vulnerabilities affecting the same vendor(s)