By weakness (CWE)
CWE-298: related vulnerabilities
CVEs classified under CWE-298. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
1 published vulnerability
- CVE-2024-1248MEDIUM 4.8
A vulnerability in federated authentication systems allows an attacker to hijack and reassign user roles when a federated identity provider has silent just-in-time account provisioning enabled. If a federated user shares a username with an existing local account, the provisioning process can overwrite the local user's roles with whatever the federated system assigns. An attacker needs to know a legitimate local username and have access to a federated identity provider configured with silent JIT provisioning to execute this attack. The impact is limited to role changes (typically to minimal access levels) rather than full account takeover.