By weakness (CWE)

CWE-298: related vulnerabilities

CVEs classified under CWE-298. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

1 published vulnerability

  • CVE-2024-1248MEDIUM 4.8

    A vulnerability in federated authentication systems allows an attacker to hijack and reassign user roles when a federated identity provider has silent just-in-time account provisioning enabled. If a federated user shares a username with an existing local account, the provisioning process can overwrite the local user's roles with whatever the federated system assigns. An attacker needs to know a legitimate local username and have access to a federated identity provider configured with silent JIT provisioning to execute this attack. The impact is limited to role changes (typically to minimal access levels) rather than full account takeover.