Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-22956 PoC — Vmware Workspace One Access 授权问题漏洞

Source
Associated Vulnerability
Title:Vmware Workspace One Access 授权问题漏洞 (CVE-2022-22956)
Description:Vmware Workspace One Access是美国Vmware公司的将用户身份与设备和网络信息等因素结合起来,为 Workspace One 交付的应用程序制定智能驱动的条件访问决策。 Vmware Workspace One Access存在授权问题漏洞,该漏洞是由于 OAuth2 ACS 框架中存在错误。远程攻击者可以绕过身份验证过程对应用程序进行访问。
Description
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
File Snapshot

id: CVE-2022-22956 info: name: VMware Workspace ONE Access - Authentication Bypass author: daff ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.