Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Server Side Request Forgery (SSRF) vulnerability. The vulnerability arises due to unsafe usage of the logo_uri parameter in the Dynamic Client Registration request. An unauthenticated attacker can make a HTTP request from the vulnerable server to any address in the internal network and obtain its response (which might, for example, have a JavaScript payload for resultant XSS). The issue can be exploited to bypass network boundaries, obtain sensitive data, or attack other hosts in the internal network.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Michael Stepankin OpenID-Connect-Java-Spring-Server 代码问题漏洞
Vulnerability Description
Michael Stepankin OpenID-Connect-Java-Spring-Server是GlobalMichael Stepankin开源的一个应用系统提供OpenID Connect身份提供程序以及通用OAuth 2.0授权服务器 Michael Stepankin OpenID-Connect-Java-Spring-Server 存在代码问题漏洞,攻击者可利用该漏洞可以从易受攻击的服务器向内部网络中的任何地址发出HTTP请求,并获得其响应。
CVSS Information
N/A
Vulnerability Type
N/A