CVE-2022-31690 - CVE House
Back to Database
Status published Unknown CVE-2022-31690

Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior...

Vulnerability Description

Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a request initiated by the Client (via the browser) to the Authorization Server which can lead to a privilege escalation on the subsequent approval. This scenario can happen if the Authorization Server responds with an OAuth2 Access Token Response containing an empty scope list (per RFC 6749, Section 5.1) on the subsequent request to the token endpoint to obtain the access token.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-31690

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Spring Security
Vulnerable Versions:
Spring Security (5.7 to 5.7.4 and 5.6 to 5.6.8 as well as older, unsupported versions)

Timeline

Official Publish: October 31st, 2022
Last Modified: May 8th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.