ForgeRock / openam-community-edition

Access Management - AuthN, AuthZ, SSO, Fedaration
https://forgerock.github.io/openam-community-edition/
123 stars 60 forks source link

Security vulnerability #53

Open dreed12 opened 6 years ago

dreed12 commented 6 years ago

ForgeRock's AM/OpenAM Security Advisory #201801 notes that a vulnerability that also affects the OpenAM 11.0.3 Community Edition has been discovered.

FireBurn commented 6 years ago

As there's no access to the trunk / master branch and Forgerock have said they won't be releasing backported patches to the community edition I'm not sure how to fix this.

FireBurn commented 6 years ago

I think the problem probably lies in openam-ui-ria/src/main/js/org/forgerock/openam/ui/user/login/AuthNDelegate.js the output must be different if the user exists compared to if it doesn't