Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6hc9-cf8x-hf83

Опубликовано: 04 окт. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Quarkus OIDC can leak both ID and access tokens

A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens.

Пакеты

Наименование

io.quarkus:quarkus-oidc

maven
Затронутые версииВерсия исправления

< 2.13.0.Final

2.13.0.Final

Наименование

io.quarkus:quarkus-oidc

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.1.0.Final

3.1.0.Final

EPSS

Процентиль: 52%
0.00291
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
redhat
почти 3 года назад

A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens.

CVSS3: 7.5
nvd
больше 2 лет назад

A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens.

EPSS

Процентиль: 52%
0.00291
Низкий

7.5 High

CVSS3

Дефекты

CWE-200