PT-2021-17521 · Mitre · Mitreid Connect

Published

2021-02-23

·

Updated

2022-12-02

·

CVE-2021-27582

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MITREid Connect versions through 1.3.3
Description The OpenID Connect server implementation for MITREid Connect contains a Mass Assignment vulnerability, also known as Autobinding. This issue arises due to the unsafe usage of the @ModelAttribute annotation during the OAuth authorization flow. As a result, HTTP request parameters can affect an authorizationRequest.
Recommendations For versions through 1.3.3, consider disabling the OAuthConfirmationController until a patch is available to prevent exploitation of the Mass Assignment vulnerability. Restrict access to the org/mitre/oauth2/web/OAuthConfirmationController.java to minimize the risk of exploitation. Avoid using the @ModelAttribute annotation in the affected OAuth authorization flow until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2021-27582
GHSA-8P36-Q63G-68QH

Affected Products

Mitreid Connect