未经验证的客户端环境 URL 导致 OAuth 授权码和 PKCE 码验证器泄露,攻击者可利用注入的 OIDC 身份提供商配置接管用户账户。在 Eclipse Ditto 的 Ditto Explorer 应用(受影响的版本范围为 3.6.0 至 3.9.7)中,攻击者可通过构造恶意链接,设置一个由攻击者控制的 OIDC 身份提供商,并启用自动单点登录(autoSso)功能。 当用户点击该链接时,用户界面(UI)会向真正的身份提供商发起登录请求,但在获取授权码后,会与 PKCE 的 code_verifier 一起
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Ditto | Ditto Explorer UI | 3.6.0≤ 3.9.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Ditto | Ditto Explorer UI | 3.6.0 ~ 3.9.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet