QID 996906
Date Published: 2024-01-30
QID 996906: Java (Maven) Security Update for org.picketlink:picketlink-tomcat-common (GHSA-9qhq-j4xm-cw48)
The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.7.1.Final does not properly check role based authorization, which allows remote authenticated users to gain access to restricted application resources via a (1) direct request or (2) request through an SP initiated flow.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9qhq-j4xm-cw48 for updates and patch information.
Vendor References
- GHSA-9qhq-j4xm-cw48 -
github.com/advisories/GHSA-9qhq-j4xm-cw48
CVEs related to QID 996906
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9qhq-j4xm-cw48 | org.picketlink:picketlink-tomcat-common |
|