← Back

CVE-2024-1248

nvd nist
Published: Jul 4, 2026Modified: Jul 9, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.

Affected (13)

5 products
Api Manager
Identity Server
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 3.0.0 to 3.0.0.153
From 3.1.0 to 3.1.0.267
From 3.2.0 to 3.2.0.351
From 4.0.0 to 4.0.0.269
From 4.1.0 to 4.1.0.169
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 5.10.0 to 5.10.0.284
From 5.11.0 to 5.11.0.321
From 5.8.0 to 5.8.0.101
From 5.9.0 to 5.9.0.138
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 5.10.0 to 5.10.0.280
From 5.9.0 to 5.9.0.148
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0.0 to 2.0.0.313
From 2.0.0 to 2.0.0.333

References (1)

Timeline

No history available yet.