pac4j-oidc 在 6.5.6 之前的版本在接受 OIDC 回调时,允许仅携带访问令牌(access token)而未经过授权码或 ID 令牌校验。攻击者可以利用为其他客户端签发的访问令牌来创建经过身份验证的会话,而系统未对颁发者(issuer)、受众(audience)、nonce 或主题(subject)进行正确校验。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82463 | 8.1 HIGH | pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check |
| CVE-2026-82461 | 8.1 HIGH | pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token |
| CVE-2026-82464 | 6.1 MEDIUM | pac4j-core before 6.5.6 Open Redirect via Backslash Logout |
| CVE-2026-82465 | 5.3 MEDIUM | pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest |
No comments yet