Количество 2
Количество 2
CVE-2021-27582
org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Mass Assignment (aka Autobinding) vulnerability. This arises due to unsafe usage of the @ModelAttribute annotation during the OAuth authorization flow, in which HTTP request parameters affect an authorizationRequest.
GHSA-8p36-q63g-68qh
Autobinding vulnerability in MITREid Connect
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-27582 org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Mass Assignment (aka Autobinding) vulnerability. This arises due to unsafe usage of the @ModelAttribute annotation during the OAuth authorization flow, in which HTTP request parameters affect an authorizationRequest. | CVSS3: 9.1 | 1% Низкий | почти 5 лет назад | |
GHSA-8p36-q63g-68qh Autobinding vulnerability in MITREid Connect | CVSS3: 9.1 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу