WrenSecurity / wrenam

Community fork of OpenAM, an authentication and authorization system originally developed by ForgeRock.
Other
43 stars 27 forks source link

[CVE-2018-0696] Perform authorization during KBA questions change. #125

Closed karelmaxa closed 1 year ago

karelmaxa commented 1 year ago

This PR adds a security check to /selfservice/user endpoint to resolve the security vulnerability published as a CVE-2018-0696.

I was able to reproduce the exploit using the current version built with JDK 17.