Use of static encryption key material allows forging an...
High severity
Unreviewed
Published
May 5, 2022
to the GitHub Advisory Database
•
Updated Jul 4, 2023
Description
Published by the National Vulnerability Database
May 4, 2022
Published to the GitHub Advisory Database
May 5, 2022
Last updated
Jul 4, 2023
Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials.
References