VDB
EN
MEDIUM

GHSA-c556-q2mh-477v

OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`

상세

OpenAM (Open Identity Platform) is an open-source Identity and Access Management (IAM) platform derived from ForgeRock OpenAM, providing SSO, OAuth2, SAML, and OpenID Connect capabilities. It is widely deployed in enterprise environments as a central authentication gateway.

The `/sessionservice` endpoint, used for internal session management operations, does not sufficiently restrict the URLs that authenticated users may register for session event notifications. Under certain conditions, this may result in outbound server-side requests to attacker-controlled destinations, potentially exposing session-related data.

This behavior results in a **server-side request forgery (SSRF)** vulnerability, where an authenticated attacker can trigger outbound requests to arbitrary destinations.

## Credit

Discovered by **JD-Security SHENYI Team**

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Maven / org.openidentityplatform.openam:openam-core
최초 영향 버전: 0 수정 버전: 16.1.1
수정 # pom.xml: bump <version>16.1.1</version> for org.openidentityplatform.openam:openam-core

참고