{"id":"CVE-2015-3158","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-3158","summary":"PicketLink does not properly check role based authorization","details":"The `invokeNextValve` function in `identity/federation/bindings/tomcat/idp/AbstractIDPValve.java` in PicketLink before 2.7.1.Final does not properly check role based authorization, which allows remote authenticated users to gain access to restricted application resources via a (1) direct request or (2) request through an SP initiated flow.","published":"2022-05-17T04:09:07Z","modified":"2024-12-06T05:39:59.338894Z","cvss":null,"epss":{"score":0.01913,"percentile":0.78603,"asOf":"2026-09-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.picketlink:picketlink-tomcat-common","fixedVersion":"2.7.1.Final"}],"fix":{"url":"https://github.com/picketlink/picketlink-bindings/pull/124","label":"picketlink/picketlink-bindings#124"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3158"},{"type":"WEB","url":"https://github.com/picketlink/picketlink-bindings/pull/124"},{"type":"WEB","url":"https://github.com/picketlink/picketlink-bindings/commit/ae6ff4adfc562880e714a089983054b47610ecec"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1216123"},{"type":"PACKAGE","url":"https://github.com/picketlink/picketlink-bindings"},{"type":"WEB","url":"https://issues.jboss.org/browse/PLINK-708"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1669.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1670.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1671.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1672.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1673.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-06T05:39:59.338894Z"}}