CVE-2021-44878 describes a vulnerability in pac4j versions up to 5.3.0 where the OpenID Connect provider fails to properly validate ID tokens when the "none" algorithm is supported. This allows an attacker to bypass token validation by injecting a malformed ID token with an empty signature. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high impact on integrity, as it allows for unauthorized access or manipulation. There is no confidentiality or availability impact. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.5CPE matchmatch criteria | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.3.1CPE matchmatch criteria | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.