CVE-2024-12056

CVSS V2 None CVSS V3 None
Description
The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment. Exploitation requires valid credentials and does not permit the attacker to bypass user privileges.
Overview
  • CVE ID
  • CVE-2024-12056
  • Assigner
  • arcinfo
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-04T14:30:35.838Z
  • Last Modified Date
  • 2024-12-04T15:00:50.503Z
References
Reference URL Reference Tags
https://www.pcvue.com/security/security/#SB2024-4 vendor-advisory
History
Created Old Value New Value Data Type Notes
2024-12-05 13:22:45 Added to TrackCVE