GHSA-cm72-j98h-q99gCriticalCVSS 8.6
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom...
🔗 CVE IDs covered (1)
📋 Description
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.