216.73.217.22

CVE-2025-53003

· Published 01/07/2025 02:15 · Modified 01/07/2025 14:15

Labels: CVE-2025-53003 2025-07-01CVE-2025-53003CWE-200[email protected]

Essential information

Published
01/07/2025 02:15
Modified
01/07/2025 14:15
Author
Creator
CVSS
8.2 HIGH (v3) 8.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without scope verification. This has a large internal surface attack area that exposes all sorts of information from the IDP including clients, users, scripts ..etc. This issue has been patched in version 1.8.0. A workaround for this vulnerability involves users forking and building the config api, patching it in their system following commit 92eea4d.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
janssen / janssen project cpe:2.3:a:janssen:janssen_project:*:*:*:*:*:*:*:*

References