CVE-2022-34155: WordPress OAuth Single Sign On – SSO (OAuth Client) Plugin <= 6.23.3 is vulnerable to Broken Authentication
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34155?
The severity of CVE-2022-34155 is high (8.8).
What is the affected software for CVE-2022-34155?
The affected software for CVE-2022-34155 is the miniOrange OAuth Single Sign On - SSO (OAuth Client) plugin version up to and excluding 6.23.4.
What is the vulnerability description for CVE-2022-34155?
CVE-2022-34155 is an Improper Authentication vulnerability in the miniOrange OAuth Single Sign On - SSO (OAuth Client) plugin that allows authentication bypass.
How can I fix CVE-2022-34155?
To fix CVE-2022-34155, upgrade to version 6.23.4 or later of the miniOrange OAuth Single Sign On - SSO (OAuth Client) plugin.
What is the Common Weakness Enumeration (CWE) for CVE-2022-34155?
The Common Weakness Enumeration (CWE) for CVE-2022-34155 is CWE-287 (Improper Authentication).