openam-jp / openam

Other
32 stars 15 forks source link

Broken Access Control #251

Closed tsujiguchitky closed 2 years ago

tsujiguchitky commented 2 years ago

Description

PLL servlet endpoints has a broken access control vulnerability. It may be possible to access to other users' session tokens.

This may be the same vulnerability announced as CVE-2021-4201.

Reference