Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mc9v-rq2q-h4r4

Опубликовано: 04 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 2.3

Описание

The Client secret is not checked when using the OAuth Password grant type.

By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment. Exploitation requires valid credentials and does not permit the attacker to bypass user privileges.

The Client secret is not checked when using the OAuth Password grant type.

By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment. Exploitation requires valid credentials and does not permit the attacker to bypass user privileges.

EPSS

Процентиль: 11%
0.00038
Низкий

2.3 Low

CVSS4

Дефекты

CWE-358

Связанные уязвимости

nvd
около 1 года назад

The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment. Exploitation requires valid credentials and does not permit the attacker to bypass user privileges.

EPSS

Процентиль: 11%
0.00038
Низкий

2.3 Low

CVSS4

Дефекты

CWE-358