boruta is vulnerable to Improper Isolation
83
High Risk
Boruta.Openid.register_client/3 forwards caller-supplied registration parameters into the administrative client-creation path after only rewriting a few OIDC keys, with no allowlist separating public registration metadata from admin-only controls. An unauthenticated caller who can reach a network endpoint that exposes this function can register an OAuth client with admin-reserved settings such as grant types, scopes, PKCE, revocation flags, and token lifetimes. That over-privileged client can then obtain tokens and exercise capabilities the deployment intended to reserve for administrators. The fix restricts dynamic registration so public callers cannot set administrative client fields.
You are affected if you are using a version that falls within the vulnerable range and expose Boruta.Openid.register_client/3 on a network endpoint without a trusted initial access token or a strict server-side parameter allowlist.
boruta is vulnerable to Improper Isolation in versions 2.3.0 - 2.3.6.
Upgrade the boruta library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.