openam-oauth2 is vulnerable to Server-Side Request Forgery (SSRF)
48
Medium Risk
The OpenID Connect dynamic client registration endpoint fetches the client-supplied sector_identifier_uri without validating the URL scheme, host, or address. This lets a caller make the server issue an HTTP GET to an arbitrary URL. When open dynamic client registration is enabled it is exploitable without authentication, and otherwise any holder of a valid access token can trigger it, reaching internal services and cloud metadata endpoints. The fix validates the URI before fetching, restricting it to https and blocking private, loopback, and link-local addresses.
You are affected if you are using a version that falls within the vulnerable range.
openam-oauth2 is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 16.1.1.
Upgrade the org.openidentityplatform.openam:openam-oauth2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant