org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Mass Assignment (aka Autobinding) vulnerability. This arises due to unsafe usage of the @ModelAttribute annotation during the OAuth authorization flow, in which HTTP request parameters affect an authorizationRequest.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.mitre:openid-connect-parent(Maven) | 0 | N/A | N/A |
CVSS Metrics