PT-2023-4017 · Miniorange · Miniorange Oauth Single Sign On – Sso

István Márton

+1

·

Published

2023-05-24

·

Updated

2023-07-27

·

CVE-2022-34155

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin versions through 6.23.3
Description The issue is related to an Improper Authentication vulnerability in the miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin, which allows Authentication Bypass. This can enable a remote attacker to bypass existing security restrictions.
Recommendations For versions through 6.23.3, update to a version later than 6.23.3 to resolve the issue. As a temporary workaround, consider restricting access to the plugin until a patch is available.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-04315
CVE-2022-34155

Affected Products

Miniorange Oauth Single Sign On – Sso