CVE-2024-1248

MEDIUMCVSS 5.3/10EPSS 0.21%

Last modified

CVE-2024-1248 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS Probability
0.21%

10.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Wso2Api Manager>= 3.0.0, < 3.0.0.153
Wso2Api Manager>= 3.1.0, < 3.1.0.267
Wso2Api Manager>= 3.2.0, < 3.2.0.351
Wso2Api Manager>= 4.0.0, < 4.0.0.269
Wso2Api Manager>= 4.1.0, < 4.1.0.169
Wso2Identity Server>= 5.8.0, < 5.8.0.101
Wso2Identity Server>= 5.9.0, < 5.9.0.138
Wso2Identity Server>= 5.10.0, < 5.10.0.284
Wso2Identity Server>= 5.11.0, < 5.11.0.321
Wso2Identity Server As Key Manager>= 5.9.0, < 5.9.0.148
Wso2Identity Server As Key Manager>= 5.10.0, < 5.10.0.280
Wso2Open Banking Am>= 2.0.0, < 2.0.0.313
Wso2Open Banking Iam>= 2.0.0, < 2.0.0.333

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-1248?
The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.
How severe is CVE-2024-1248?
CVE-2024-1248 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2024-1248?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2024

Are you affected by CVE-2024-1248?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST