In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.
Start learningUpgrade org.openidentityplatform.opendj:opendj-server-legacy to version 5.1.2 or higher.
Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key in the SASL PLAIN authentication process. An attacker can gain unauthorized access to arbitrary directory user accounts by supplying an authorization identity (authzid) that resolves to a different user, provided they possess the proxied-auth privilege but lack the required proxy ACI scope grant. This allows impersonation of any resolvable non-root identity beyond intended access controls.
This vulnerability can be mitigated by restricting or revoking the proxied-auth privilege until the issue is resolved.