Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4v5x-9m47-cqr2

Опубликовано: 09 дек. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.2

Описание

Duplicate Advisory: WildFly Elytron OpenID Connect Client Extension authorization code injection attack

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-5565-3c98-g6jc. This link is maintained to preserve external references.

Original Description

A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.

Пакеты

Наименование

org.wildfly:wildfly-elytron-oidc-client-subsystem

maven
Затронутые версииВерсия исправления

<= 34.0.1.Final

Отсутствует

4.2 Medium

CVSS3

Дефекты

CWE-345

4.2 Medium

CVSS3

Дефекты

CWE-345