Mitreid is an OpenID Connect reference implementation and authorization server that provides identity federation and token management for enterprise and research environments. Its vulnerability footprint centers on the Connect product with a consistent signal around web-application input handling, including cross-site scripting, prototype pollution, and server-side request forgery vulnerabilities that reflect the risks inherent to an HTTP-facing authentication gateway. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mitreid over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27582CRITICAL org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Mass Assignment (aka Autobinding) vul | Feb 23, 2021 | 9.1 | 28 | NO | NO |
CVE-2021-26715CRITICAL The OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Server Side Request Forgery (SSRF) vulnerability. The vulnerability arises due to unsafe usage | Mar 25, 2021 | 9.1 | 27 | NO | NO |
CVE-2020-5497MEDIUM The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. | Jan 4, 2020 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mitreid.
Media articles that mention a CVE ID that affects a product developed by Mitreid — matched by CVE ID, not by vendor name.