Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-12369

Опубликовано: 09 дек. 2024
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.

Отчет

Red Hat has evaluated this vulnerability. This affects the OIDC Client when using RHSSO OIDC Adapter with EAP 7.x or elytron-oidc-client with EAP 8.x.

Меры по смягчению последствий

Currently, no mitigation is currently available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakorg.jboss.eap/wildfly-elytron-oidc-client-subsystemNot affected
Red Hat JBoss Enterprise Application Platform 7org.wildfly/wildfly-elytron-oidc-client-subsystemWill not fix
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-apache-commons-ioFixedRHSA-2025:398917.04.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-bouncycastleFixedRHSA-2025:398917.04.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-eap-product-conf-parentFixedRHSA-2025:398917.04.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-hibernateFixedRHSA-2025:398917.04.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-ironjacamarFixedRHSA-2025:398917.04.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-jakarta-enterprise-concurrentFixedRHSA-2025:398917.04.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-jsf-implFixedRHSA-2025:398917.04.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-reactive-streamsFixedRHSA-2025:398917.04.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=2331178elytron-oidc-client: OIDC Authorization Code Injection

EPSS

Процентиль: 54%
0.00308
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
nvd
около 1 года назад

A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.

CVSS3: 4.2
github
11 месяцев назад

WildFly Elytron OpenID Connect Client ExtensionOIDC authorization code injection attack

EPSS

Процентиль: 54%
0.00308
Низкий

4.2 Medium

CVSS3