In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.
Start learningUpgrade io.openremote:openremote-manager to version 1.24.2 or higher.
Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key in the UserResourceImpl process. An attacker can access sensitive user profile information, client roles, and realm roles across different realms by supplying a valid user UUID from another realm in the REST API path. This enables cross-tenant user enumeration and reconnaissance by authenticated users with the appropriate role.