Duende.IdentityServer
NuGet2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting Duende.IdentityServerpage 1 of 1
- CVE-2024-39694MEDIUMCVSS 4.7EG 4.7✓ Fixed in 6.0.52024-07-31
vulnerable: 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url…
- CVE-2024-49755LOWCVSS 3.1EG 3.1✓ Fixed in 7.0.82024-10-28
vulnerable: 7.0.0 ... 7.0.7 (8 versions)
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. IdentityServer's local API authentication handler performs insufficient validation of the cnf claim in DPoP access tokens. This allows an attacker to use …
Check whether Duende.IdentityServer is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for Duende.IdentityServer CVEs against the assets you own.
Start Free Scan →