{"id":"CVE-2025-53003","aliases":["GHSA-373j-mhpf-84wg"],"url":"https://o3.security/vulnerability/CVE-2025-53003","summary":"Janssen Config API returns results without scope verification","details":"The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without scope verification. This has a large internal surface attack area that exposes all sorts of information from the IDP including clients, users, scripts ..etc. This issue has been patched in version 1.8.0. A workaround for this vulnerability involves users forking and building the config api, patching it in their system following commit 92eea4d.","published":"2025-07-01T01:22:05.855Z","modified":"2026-08-12T15:16:58.813672Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"io.jans:jans-config-api-server","fixedVersion":"1.8.0"}],"fix":{"url":"https://github.com/JanssenProject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1","label":"JanssenProject/jans@92eea4d"},"references":[{"type":"WEB","url":"https://github.com/JanssenProject/jans/releases/tag/v1.8.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53003.json"},{"type":"ADVISORY","url":"https://github.com/JanssenProject/jans/security/advisories/GHSA-373j-mhpf-84wg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53003"},{"type":"REPORT","url":"https://github.com/JanssenProject/jans/issues/11575"},{"type":"FIX","url":"https://github.com/JanssenProject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:16:58.813672Z"}}