OpenAM: Pre-authentication Remote Code Execution Vulnerability
An early warning has been issued for a critical pre-authentication remote code execution vulnerability affecting OpenAM versions up to 16.1.1. The issue reportedly allows an attacker to execute arbitrary code on the server by exploiting an XML endpoint that lacks validation.
What happened
A pre-authentication remote code execution vulnerability has been reported in OpenAM versions up to 16.1.1. The vulnerability, tracked as GHSA-WG5R-WC3X-39VC, affects the openam-core (maven) component. The issue arises from the remote authentication endpoint, which accepts an XML element that names an arbitrary Java class. The server then loads and instantiates this class without validation, allowing an attacker to run code on the server if the default configuration is used.
The vulnerability is under investigation, and it is recommended to upgrade to OpenAM version 16.1.2 to mitigate the risk. Users should consult the primary source [GHSA-wg5r-wc3x-39vc] for more detailed information and to verify the specifics of the vulnerability and the affected versions.
Professional software engineers assessing their exposure should review their OpenAM configurations and ensure they are running a version that is not affected by this vulnerability. It is crucial to apply the recommended upgrade and to monitor for any further updates or patches that may be released as the investigation continues.
How 0Day mitigates this
openam-core is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.