Show filters
70 Total Results
Displaying 41-50 of 70
Sort by:
Attacker Value
Unknown

CVE-2019-1003099

Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
Attacker Value
Unknown

CVE-2019-1003098

Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server.
0
Attacker Value
Unknown

CVE-2019-9837

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redirect_uri field in an OAuth authorization request (that results in an error response) with the 'openid' scope and a prompt=none value. This allows phishing attacks against the authorization flow.
0
Attacker Value
Unknown

CVE-2019-1003021

Disclosure Date: February 06, 2019 (last updated October 26, 2023)
An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlier in OicSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client secret.
0
Attacker Value
Unknown

CVE-2017-6059

Disclosure Date: April 12, 2017 (last updated November 08, 2023)
Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request.
Attacker Value
Unknown

CVE-2017-7591

Disclosure Date: April 09, 2017 (last updated November 26, 2024)
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/.
0
Attacker Value
Unknown

CVE-2017-7590

Disclosure Date: April 09, 2017 (last updated November 26, 2024)
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to persistent cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by a crafted Managed Object Name.
0
Attacker Value
Unknown

CVE-2017-7589

Disclosure Date: April 09, 2017 (last updated November 26, 2024)
In OpenIDM through 4.0.0 before 4.5.0, the info endpoint may leak sensitive information upon a request by the "anonymous" user, as demonstrated by responses with a 200 HTTP status code and a JSON object containing IP address strings. This is related to a missing access-control check in bin/defaults/script/info/login.js.
0
Attacker Value
Unknown

CVE-2017-6062

Disclosure Date: March 02, 2017 (last updated November 08, 2023)
The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "OIDCUnAuthAction pass" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.
0
Attacker Value
Unknown

CVE-2017-6413

Disclosure Date: March 02, 2017 (last updated November 08, 2023)
The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.
0