OpenID kayıtları
openid üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %42,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation1
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-11027İstismar yok | Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw.openid · ruby-openid | Kritik9,8 | — | %3,0 | 10 Haz 2019 |
30İzleyin | CVE-2007-1652İstismar yok | OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user's personal information to this site, andopenid · openid | Yüksek7,5 | — | %1,3 | 23 Mar 2007 |
28İzleyin | CVE-2007-5173Kavram kanıtı | PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute openid · openid · CWE-94 | Orta6,8 | — | %2,8 | 3 Eki 2007 |
27İzleyin | CVE-2007-1651İstismar yok | Cross-site request forgery (CSRF) vulnerability in OpenID allows remote attackers to restore the login session of a user on an OpenID enableopenid · openid | Orta6,8 | — | %1,4 | 23 Mar 2007 |
24İzleyin | CVE-2008-3280Kavram kanıtı | It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Randopenid · openid · CWE-338 | Orta5,9 | — | %4,0 | 21 May 2021 |
24İzleyin | CVE-2011-4314İstismar yok | message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Fopenid · openid4java · CWE-20 | Orta5,8 | — | %3,1 | 27 Oca 2012 |
24İzleyin | CVE-2019-9837İstismar yok | Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redireopenid · openid connect · CWE-601 | Orta6,1 | — | %1,3 | 21 Mar 2019 |
- CVE-2019-1102740Planlayın
Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw.
KritikCVSS 9,8İstismar yokEPSS %3openid · ruby-openid10 Haz 2019
- CVE-2007-165230İzleyin
OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user's personal information to this site, and
YüksekCVSS 7,5İstismar yokEPSS %1openid · openid23 Mar 2007
- CVE-2007-517328İzleyin
PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute
OrtaCVSS 6,8Kavram kanıtıEPSS %3openid · openid3 Eki 2007
- CVE-2007-165127İzleyin
Cross-site request forgery (CSRF) vulnerability in OpenID allows remote attackers to restore the login session of a user on an OpenID enable
OrtaCVSS 6,8İstismar yokEPSS %1openid · openid23 Mar 2007
- CVE-2008-328024İzleyin
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Rand
OrtaCVSS 5,9Kavram kanıtıEPSS %4openid · openid21 May 2021
- CVE-2011-431424İzleyin
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay F
OrtaCVSS 5,8İstismar yokEPSS %3openid · openid4java27 Oca 2012
- CVE-2019-983724İzleyin
Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redire
OrtaCVSS 6,1İstismar yokEPSS %1openid · openid connect21 Mar 2019