Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1, IdTokenClaimsValidator skips `aud` claim validation if token is issued by same identity issuer/provider. Any OIDC setup using Micronaut where multiple OIDC applications exists for the same issuer but token auth are not meant to be shared. This issue has been patched in versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-09T13:30:26.387Z
Updated: 2024-09-19T14:39:04.617Z
Reserved: 2023-06-27T15:43:18.385Z
Link: CVE-2023-36820
Vulnrichment
Updated: 2024-08-02T17:01:09.850Z
NVD
Status : Modified
Published: 2023-10-09T14:15:10.640
Modified: 2024-11-21T08:10:40.067
Link: CVE-2023-36820
Redhat
No data.