CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
AI Score
Confidence
Low
EPSS
Percentile
15.5%
A flaw was found in JBoss EAP. When an OIDC app that serves multiple tenants attempts to access the second tenant, it should prompt the user to log in again since the second tenant is secured with a different OIDC configuration. The underlying issue is in OidcSessionTokenStore when determining if a cached token should be used or not. This logic needs to be updated to take into account the new “provider-url” option in addition to the “realm” option.
Vendor | Product | Version | CPE |
---|---|---|---|
org.wildfly.security | wildfly-elytron-http-oidc | * | cpe:2.3:a:org.wildfly.security:wildfly-elytron-http-oidc:*:*:*:*:*:*:*:* |
access.redhat.com/errata/RHSA-2024:3580
access.redhat.com/errata/RHSA-2024:3581
access.redhat.com/errata/RHSA-2024:3583
access.redhat.com/security/cve/CVE-2023-6236
bugzilla.redhat.com/show_bug.cgi?id=2250812
github.com/advisories/GHSA-jpmx-996v-48fm
github.com/wildfly-security/wildfly-elytron/commit/6e94ec3476a279c0a130186209c50a2991ba4c84
nvd.nist.gov/vuln/detail/CVE-2023-6236