Skip to main content

Vendor/product archive

mitreid / connect CVEs

Beta · best-effort

3 CVEs tagged to mitreid / connect2 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2021-26715

Published Mar 25, 2021

The OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Server Side Request Forgery (SSRF) vulnerability. The vulnerability arises due to unsafe usag…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27582

Published Feb 23, 2021

org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Mass Assignment (aka Autobinding) vu…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-5497

Published Jan 4, 2020

The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1