漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Roadiz OpenID Connect nonce generated but never validated — ID token replay attack
Vulnerability Description
Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and 2.7.18, the roadiz/openid package generates an OIDC nonce in OAuth2LinkGenerator::generate() and includes it in the authorization request sent to the identity provider, but never stores it and never validates it on the callback. The OpenIdJwtConfigurationFactory validation chain does not include a nonce constraint, and OpenIdAuthenticator::authenticate() never checks the nonce claim in the returned ID token against a stored value. This issue has been patched in versions 2.3.43, 2.5.45, 2.6.31, and 2.7.18.
CVSS Information
N/A
Vulnerability Type
对数据真实性的验证不充分
Vulnerability Title
Roadiz Document base system 数据伪造问题漏洞
Vulnerability Description
Roadiz Document base system是Roadiz开源的一个基于文档的HTML模板渲染系统。 Roadiz Document base system 2.3.43之前版本、2.5.45之前版本、2.6.31之前版本和2.7.18之前版本存在数据伪造问题漏洞,该漏洞源于OAuth2LinkGenerator::generate()生成OIDC nonce但从未存储且从未在回调中验证,OpenIdJwtConfigurationFactory验证链不包含nonce约束,且OpenIdAuth
CVSS Information
N/A
Vulnerability Type
N/A