Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-40571

Опубликовано: 13 мая 2025
Источник: nvd
CVSS3: 2.2
EPSS Низкий

Описание

A vulnerability has been identified in Mendix OIDC SSO (Mendix 10 compatible) (All versions < V4.1.0), Mendix OIDC SSO (Mendix 10.12 compatible) (All versions < V4.0.1), Mendix OIDC SSO (Mendix 9 compatible) (All versions < V3.3.0). The Mendix OIDC SSO module grants read and write access to all tokens exclusively to the Administrator role and could result in privilege misuse by an adversary modifying the module during Mendix development.

EPSS

Процентиль: 10%
0.00036
Низкий

2.2 Low

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 2.2
github
9 месяцев назад

A vulnerability has been identified in Mendix OIDC SSO (Mendix 10 compatible) (All versions < V4.0.0), Mendix OIDC SSO (Mendix 9 compatible) (All versions). The Mendix OIDC SSO module grants read and write access to all tokens exclusively to the Administrator role and could result in privilege misuse by an adversary modifying the module during Mendix development.

EPSS

Процентиль: 10%
0.00036
Низкий

2.2 Low

CVSS3

Дефекты

CWE-266