Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-12369

Опубликовано: 09 дек. 2024
Источник: nvd
CVSS3: 4.2
EPSS Низкий

Описание

A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.

EPSS

Процентиль: 54%
0.00308
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 4.2
redhat
около 1 года назад

A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.

CVSS3: 4.2
github
11 месяцев назад

WildFly Elytron OpenID Connect Client ExtensionOIDC authorization code injection attack

EPSS

Процентиль: 54%
0.00308
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-345