← back
CVE-2016-4977observed exploitation

CVE-2016-4977

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 79%
from disclosure to weapon998 days
Published on NVDMay 25
1st PoC+998d
VulnCheck+2638d
exploitation probability
79%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via the crafting of the value for response_type.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.