Skip to content

SNYK-JAVA-COMNIMBUSDS-1243767: Bump com.nimbusds:oauth2-oidc-sdk to version 9.3.1 or higher #9568

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
candrews opened this issue Apr 8, 2021 · 1 comment
Assignees
Labels
status: invalid An issue that we don't feel is valid type: bug A general bug

Comments

@candrews
Copy link
Contributor

candrews commented Apr 8, 2021

Affected versions of com.nimbusds:oauth2-oidc-sdk are vulnerable to XML External Entity (XXE) Injection via the SAML2AssertionValidator method. Access to external entities was not disabled in XML parsing.

Upgrade com.nimbusds:oauth2-oidc-sdk to version 9.3.1 or higher.

The current latest release of Spring Security, 5.4.5, depends upon com.nimbusds:oauth2-oidc-sdk version 8.36.1

https://snyk.io/vuln/SNYK-JAVA-COMNIMBUSDS-1243767

@candrews candrews added status: waiting-for-triage An issue we've not yet triaged type: bug A general bug labels Apr 8, 2021
@rwinch rwinch added status: invalid An issue that we don't feel is valid and removed status: waiting-for-triage An issue we've not yet triaged labels Apr 8, 2021
@rwinch
Copy link
Member

rwinch commented Apr 8, 2021

Thanks for the report. The fix to nimbus was back ported to oauth2-oidc-sdk 8.36.1 and 7.1.3. For additional details please see the related discussion at #9399 (comment)

@rwinch rwinch closed this as completed Apr 8, 2021
@rwinch rwinch self-assigned this Apr 8, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status: invalid An issue that we don't feel is valid type: bug A general bug
Projects
None yet
Development

No branches or pull requests

2 participants