PT-2017-17820 · Forgerock · Openid

Publicado

2017-04-09

·

Atualizado

2017-04-13

·

CVE-2017-7589

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenIDM versions prior to 4.5.0
Description The issue is related to a missing access-control check in the info endpoint, which may leak sensitive information when a request is made by the "anonymous" user. This can be demonstrated by responses with a 200 HTTP status code and a JSON object containing IP address strings, specifically in the script located at bin/defaults/script/info/login.js.
Recommendations For OpenIDM versions prior to 4.5.0, update to version 4.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the info endpoint to prevent potential information leakage.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7589

Produtos afetados

Openid