A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attackers own session with the client with a victims identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-apache-commons-io-0:2.16.1-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-bouncycastle-0:1.80.0-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-eap-product-conf-parent-0:800.7.0-2.GA_redhat_00002.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-hibernate-0:6.2.35-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-ironjacamar-0:3.0.13-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-jakarta-enterprise-concurrent-0:3.0.1-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-jsf-impl-0:4.0.11-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-reactive-streams-0:1.0.4-3.redhat_00004.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-reactivex-rxjava-0:3.1.10-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-weld-core-0:5.1.5-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-wildfly-0:8.0.7-3.GA_redhat_00004.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-wildfly-elytron-0:2.2.9-1.Final_redhat_00001.1.el8eap | * |