CVE-2024-12056

LOW

OAuth Client - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment. Exploitation requires valid credentials and does not permit the attacker to bypass user privileges.

Scores

CVSS v4 2.3
EPSS 0.0005
EPSS Percentile 16.1%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/AU:N/R:U/RE:M/U:Green

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-358
Status published
Products (1)
arcinfo/PcVue 12.0 - 16.2.2
Published Dec 04, 2024
Tracked Since Feb 18, 2026