PT-2022-23534 · Gluu · Gluu Oxauth

Published

2022-09-06

·

Updated

2022-10-23

·

CVE-2022-36663

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gluu Oxauth versions prior to 4.4.1
Description The issue allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request uri parameter. This enables attackers to forge requests from the server, potentially leading to unauthorized access or information disclosure.
Recommendations For versions prior to 4.4.1, update to version 4.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the request uri parameter to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-36663
GHSA-HC94-9V26-GXWV

Affected Products

Gluu Oxauth