{"id":"CVE-2024-12369","title":"A vulnerability was found in OIDC-Client","summary":"A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stol…","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-345"],"published":"2024-12-09","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-12369","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:3989","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:3990","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:3992","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-12369","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2331178","label":"secalert@redhat.com"},{"url":"https://github.com/wildfly-security/wildfly-elytron/commit/5ac5e6bbcba58883b3cebb2ddbcec4de140c5ceb","label":"secalert@redhat.com"},{"url":"https://github.com/wildfly-security/wildfly-elytron/commit/d7754f5a6a91ceb0f4dbbbfe301991f6a55404cb","label":"secalert@redhat.com"},{"url":"https://github.com/wildfly-security/wildfly-elytron/pull/2253","label":"secalert@redhat.com"},{"url":"https://github.com/wildfly-security/wildfly-elytron/pull/2261","label":"secalert@redhat.com"}],"tags":["nvd"],"epss":0.00243,"epssPercentile":0.15771,"ingestedAt":"2026-08-04T09:39:29.538Z","slug":"CVE-2024-12369","body":"## Overview\n\nA vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}