Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8p36-q63g-68qh

Опубликовано: 13 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Autobinding vulnerability in MITREid Connect

org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Mass Assignment (aka Autobinding) vulnerability. This arises due to unsafe usage of the @ModelAttribute annotation during the OAuth authorization flow, in which HTTP request parameters affect an authorizationRequest.

Пакеты

Наименование

org.mitre:openid-connect-parent

maven
Затронутые версииВерсия исправления

<= 1.3.3

Отсутствует

EPSS

Процентиль: 69%
0.00616
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-1321
CWE-915

Связанные уязвимости

CVSS3: 9.1
nvd
почти 5 лет назад

org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Mass Assignment (aka Autobinding) vulnerability. This arises due to unsafe usage of the @ModelAttribute annotation during the OAuth authorization flow, in which HTTP request parameters affect an authorizationRequest.

EPSS

Процентиль: 69%
0.00616
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-1321
CWE-915