Could you please at least update "oauth2-oidc-sdk:9.43.6" dependency to a more recent version in "spring-security-oauth2-client" as it pulls transitively "com.nimbusds:nimbus-jose-jwt:9.37.3", which has vulnerability?
See the dependencies: https://mvnrepository.com/artifact/org.springframework.security/spring-security-oauth2-client/6.5.5 https://mvnrepository.com/artifact/com.nimbusds/oauth2-oidc-sdk/9.43.6 https://mvnrepository.com/artifact/com.nimbusds/nimbus-jose-jwt/9.37.3