openam-rest is vulnerable to Server-Side Request Forgery (SSRF)
54
Medium Risk
The entitlement listener REST endpoint registers a client-supplied url as a policy-change notification callback without validating its scheme, host, or address. When any entitlement policy is created, modified, or deleted, OpenAM issues an HTTP POST with policy metadata to every registered URL. The callback is persisted and fires on every policy change until removed, exposing policy-change metadata and enabling internal probing. The fix validates registered URLs at registration and before each notification and rejects loopback, link-local, private, and metadata addresses.
You are affected if you are using a version that falls within the vulnerable range.
openam-rest is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 16.1.1.
Upgrade the org.openidentityplatform.openam:openam-rest library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant