Threats Tagged 'cwe-298'
View all threats tagged with 'cwe-298'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-298'
Click on any threat for detailed analysis and mitigation recommendations
0 The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator. Join the discussion | CVE Database V5 | 07/04/2026, 20:38:49 UTC Added: 07/04/2026, 20:51:54 UTC |
Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the certificate expires. Join the discussion | CVE Database V5 | 12/17/2025, 12:36:24 UTC Added: 12/17/2025, 12:59:30 UTC |
0 Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the authentication logic will cause API tokens that were deleted and/or expired to be considered valid. This means that any API token that is associated with an active user account can authenticate successfully. This issue is fixed in versions 1.3.9 and 1.4.5. As a workaround, users can delete or deactivate the account associated with a deleted API token to prevent that token from authenticating. Join the discussion | CVE Database V5 | 09/09/2025, 22:06:47 UTC Added: 09/09/2025, 22:20:27 UTC |
Showing 1 to 3 of 3 results