-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from unvalidated processing of the 'request_uri' parameter. The patch added validation logic (validateRequestUri) to createJwtRequest and modified queryRequest usage. Pre-patch versions lacked: 1) Blacklist checks via AppConfiguration.requestUriBlackList 2) Client request_uri whitelist validation 3) Blocking of internal endpoints like localhost. The createJwtRequest function was vulnerable because it invoked queryRequest to fetch external content without these safeguards, and queryRequest itself performed the unsafe HTTP request.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.gluu:oxauth-common | maven | < 4.4.1 | 4.4.1 |
Ongoing coverage of React2Shell