CVE-2023-36820

MEDIUM

Micronaut Security <3.1.2-3.11.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1, IdTokenClaimsValidator skips `aud` claim validation if token is issued by same identity issuer/provider. Any OIDC setup using Micronaut where multiple OIDC applications exists for the same issuer but token auth are not meant to be shared. This issue has been patched in versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1.

Scores

CVSS v3 4.8
EPSS 0.0058
EPSS Percentile 69.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (3)
io.micronaut.security/micronaut-security-oauth2 3.11.0 - 3.11.1Maven
objectcomputing/micronaut_security 3.11.0
objectcomputing/micronaut_security < 3.1.2
Published Oct 09, 2023
Tracked Since Feb 18, 2026