PT-2023-4017 · Miniorange · Miniorange Oauth Single Sign On – Sso

·

CVE-2022-34155

·

Publicado

2023-05-24

·

Atualizado

2023-07-27

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin versions through 6.23.3
Description The issue is related to an Improper Authentication vulnerability in the miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin, which allows Authentication Bypass. This can enable a remote attacker to bypass existing security restrictions.
Recommendations For versions through 6.23.3, update to a version later than 6.23.3 to resolve the issue. As a temporary workaround, consider restricting access to the plugin until a patch is available.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04315
CVE-2022-34155

Produtos afetados

Miniorange Oauth Single Sign On – Sso