org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.framework@5.20.228 vulnerabilities

  • latest version

    7.6.7

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    1 months ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.framework package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Authentication

    Affected versions of this package are vulnerable to Improper Authentication via the Just-In-Time (JIT) provisioning process. An attacker can impersonate a legitimate user by exploiting the JIT provisioning flow when specific conditions are met.

    Note

    This is only exploitable if an Identity Provider (IDP) is configured for federated authentication with JIT provisioning enabled using the "Prompt for username, password and consent" option, and a service provider uses this IDP for federated authentication with the "Assert identity using mapped local subject identifier" flag enabled. The attacker must have a fresh valid user account in the federated IDP that has not been used earlier and knowledge of the username of a valid user in the local IDP.

    How to fix Improper Authentication?

    Upgrade org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.framework to version 5.20.254 or higher.

    [,5.20.254)