ApiFest OAuth 2.0 Server是ApiFest开源的一种 OAuth 2.0 协议的 ApiFest OAuth 2.0 Server Java 实现。 ApiFest OAuth 2.0 Server 0.3.1 版本存在安全漏洞,该漏洞源于不根据 RFC 6749 验证重定向 URI。攻击者利用该漏洞可使用受攻击者控制的被操纵的重定向 URI(redirect_uri 参数)来制作请求,从而在服务器将客户端重定向到带有授权码的被操纵的重定向 URI 时获得泄露的授权码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-33036 | Embarcadero Technologies Dev-CPP 代码问题漏洞 | |
| CVE-2022-34835 | Das U-Boot 缓冲区错误漏洞 | |
| CVE-2021-40597 | Edimax Technology IC-3140W 信任管理问题漏洞 | |
| CVE-2022-30467 | Joy ebike Wolf 安全漏洞 | |
| CVE-2022-33061 | Online Railway Reservation System SQL注入漏洞 | |
| CVE-2022-33060 | Online Railway Reservation System SQL注入漏洞 | |
| CVE-2022-33059 | Online Railway Reservation System SQL注入漏洞 | |
| CVE-2022-33058 | Online Railway Reservation System SQL注入漏洞 | |
| CVE-2022-33057 | Online Railway Reservation System SQL注入漏洞 | |
| CVE-2022-33042 | Online Railway Reservation System SQL注入漏洞 | |
| CVE-2022-32969 | MetaMask 安全漏洞 | |
| CVE-2022-34043 | NoMachine 安全漏洞 | |
| CVE-2022-33037 | Orwell-Dev-Cpp 代码问题漏洞 | |
| CVE-2022-31897 | Zoo Management System 跨站脚本漏洞 | |
| CVE-2022-33035 | NetSarang XLPD 代码问题漏洞 | |
| CVE-2022-33023 | CVA6 安全漏洞 | |
| CVE-2022-33021 | CVA6 缓冲区错误漏洞 | |
| CVE-2022-33107 | ThinkPHP 代码问题漏洞 | |
| CVE-2021-40642 | Textpattern CMS 安全漏洞 | |
| CVE-2022-29272 | Nagios XI 输入验证错误漏洞 |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet