7.6.7
8 years ago
1 months ago
Known vulnerabilities in the org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.framework package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Improper Authentication via the Just-In-Time (JIT) provisioning process. An attacker can impersonate a legitimate user by exploiting the JIT provisioning flow when specific conditions are met. Note This is only exploitable if an Identity Provider (IDP) is configured for federated authentication with JIT provisioning enabled using the "Prompt for username, password and consent" option, and a service provider uses this IDP for federated authentication with the "Assert identity using mapped local subject identifier" flag enabled. The attacker must have a fresh valid user account in the federated IDP that has not been used earlier and knowledge of the username of a valid user in the local IDP. How to fix Improper Authentication? Upgrade | [,5.20.254) |