-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from improper handling of request parameters in configuration loading. The key evidence comes from the patch which:
The original vulnerable functions lacked these safeguards, allowing attackers to override OIDC endpoints, group mappings, and provider configurations through unvalidated request parameters. This directly enabled authentication bypass and privilege escalation as described in CVE-2022-39387.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.xwiki.contrib.oidc:oidc-authenticator | maven | < 1.29.1 | 1.29.1 |
Ongoing coverage of React2Shell