CVE-2022-34298
MEDIUM5.3EPSS 45.1%NT auth module vulnerability in OpenAM
發布日:2022/6/24修改日:2023/11/8
描述
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
受影響套件(1)
- Maven/org.openidentityplatform.openam:openam-corefrom 0, < 14.6.6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
參考連結(5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-34298
- PATCHhttps://github.com/OpenIdentityPlatform/OpenAM
- WEBhttps://github.com/OpenIdentityPlatform/OpenAM/compare/14.6.5...14.6.6
- WEBhttps://github.com/OpenIdentityPlatform/OpenAM/pull/514
- WEBhttps://github.com/OpenIdentityPlatform/OpenAM/releases/tag/14.6.6