CVE-2024-12056
Client Secret not checked with OAuth Password grant type
The Client secret is not checked when using the OAuth Password grant type.
By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment.
Exploitation requires valid credentials and does not permit the attacker to bypass user privileges.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/AU:N/R:U/RE:M/U:Green
Produtos afetados
arcinfo · PcVueQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →