CVE-2025-0020: ArcGIS Hidden Functionality Allows Insecure OAuth 2.0 Based Authentication
Published May 14, 2025
·Updated
Rejected reason: “This CVE ID is Rejected and will not be used. As the CNA of record ESRI has rejected this CVE as it is not a vulnerability”
Affected Software
1 affected component
Esri ArcGIS
Remediation
Information
1. Adhere to RFC 6749 for OAuth 2.0, and additional standards such as RFC 9700.
2. Ensure there are no undocumented features (e.g., developer documentation)
Event History
May 14, 2025
CVE Published
via MITRE·07:54 AM
Rejected
via MITRE·07:54 AM
Data Sourced
via NVD·08:15 AM
Description
May 19, 2025
Rejected
via MITRE·07:07 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-0020?
CVE-2025-0020 is classified as a moderate severity vulnerability due to its potential for privilege abuse.
2
How do I fix CVE-2025-0020?
To fix CVE-2025-0020, update to the latest version of ArcGIS containing the security patch provided by Esri.
3
What causes CVE-2025-0020?
CVE-2025-0020 is caused by a violation of secure design principles that allows manipulation of hidden functionality and configuration.
4
Which versions of ArcGIS are affected by CVE-2025-0020?
CVE-2025-0020 affects certain versions of Esri ArcGIS, specifically those that utilize the impacted authentication methods.
5
What are the risks associated with CVE-2025-0020?
The risks associated with CVE-2025-0020 include unauthorized privilege escalation and potential manipulation of sensitive hidden fields.