In certain IETF OAuth 2.0-related specifications, when the JSON Web Token Profile for OAuth 2.0 Client Authentication mechanism is used, there are ambiguities in the audience values of JWTs sent to authorization servers. The affected RFCs may include RFC 7523, and also RFC 7521, RFC 7522, RFC 9101 (JAR), and RFC 9126 (PAR).
References
Configurations
No configuration.
History
07 Mar 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
03 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-305 |
03 Mar 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-03 18:15
Updated : 2025-03-07 17:15
NVD link : CVE-2025-27371
Mitre link : CVE-2025-27371
CVE.ORG link : CVE-2025-27371
JSON object : View
Products Affected
No product.
CWE
CWE-305
Authentication Bypass by Primary Weakness