First published: Tue Jul 18 2023(Updated: )
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
MiniOrange OAuth 2.0 Client for SSO | <6.23.4 |
Update to 6.23.4 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-34155 is high (8.8).
The affected software for CVE-2022-34155 is the miniOrange OAuth Single Sign On - SSO (OAuth Client) plugin version up to and excluding 6.23.4.
CVE-2022-34155 is an Improper Authentication vulnerability in the miniOrange OAuth Single Sign On - SSO (OAuth Client) plugin that allows authentication bypass.
To fix CVE-2022-34155, upgrade to version 6.23.4 or later of the miniOrange OAuth Single Sign On - SSO (OAuth Client) plugin.
The Common Weakness Enumeration (CWE) for CVE-2022-34155 is CWE-287 (Improper Authentication).