Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrv3-8mcq-ppf5

Опубликовано: 27 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.8
CVSS3: 6.5

Описание

The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentials

The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentials

EPSS

Процентиль: 1%
0.00011
Низкий

6.8 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentials

EPSS

Процентиль: 1%
0.00011
Низкий

6.8 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-312