Improper Authentication Affecting org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.framework package, versions [,5.20.254)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Authentication vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGWSO2CARBONIDENTITYFRAMEWORK-6145942
  • published7 Jan 2024
  • disclosed15 Dec 2023
  • creditNghĩa Vũ Trung

Introduced: 15 Dec 2023

CVE-2023-6837  (opens in a new tab)
CWE-287  (opens in a new tab)

How to fix?

Upgrade org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.framework to version 5.20.254 or higher.

Overview

Affected versions of this package are vulnerable to Improper Authentication via the Just-In-Time (JIT) provisioning process. An attacker can impersonate a legitimate user by exploiting the JIT provisioning flow when specific conditions are met.

Note

This is only exploitable if an Identity Provider (IDP) is configured for federated authentication with JIT provisioning enabled using the "Prompt for username, password and consent" option, and a service provider uses this IDP for federated authentication with the "Assert identity using mapped local subject identifier" flag enabled. The attacker must have a fresh valid user account in the federated IDP that has not been used earlier and knowledge of the username of a valid user in the local IDP.

CVSS Scores

version 3.1