在 Eclipse Lyo 2.0.0 到 7.0.0 版本中,当服务器支持两腿认证(2-legged authentication)时,OAuth 服务器的授权检查可能被绕过。在这种情况下,基于 Lyo 提供的 构建其授权过滤器的应用程序存在漏洞。 攻击者可以创建一个临时的受信任客户端(这是一种有效的使用场景),但该客户端无需管理员批准即可立即作为受信任客户端使用,从而清除了其临时状态。需要用户交互的三腿认证路径不受影响,并且会拒绝临时客户端。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse Lyo | 2.0.0< 7.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse Lyo | 2.0.0 ~ 7.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet