In certain IETF OAuth 2.0-related specifications, when the JSON Web Token Profile for OAuth 2.0 Client Authentication mechanism is used, there are ambiguities in the audience values of JWTs sent to authorization servers. The affected RFCs may include RFC 7523, and also RFC 7521, RFC 7522, RFC 9101 (JAR), and RFC 9126 (PAR).
History

Fri, 07 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
References

Tue, 04 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863

Mon, 03 Mar 2025 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863

Mon, 03 Mar 2025 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863 CWE-305

Mon, 03 Mar 2025 18:00:00 +0000

Type Values Removed Values Added
Description In certain IETF OAuth 2.0-related specifications, when the JSON Web Token Profile for OAuth 2.0 Client Authentication mechanism is used, there are ambiguities in the audience values of JWTs sent to authorization servers. The affected RFCs may include RFC 7523, and also RFC 7521, RFC 7522, RFC 9101 (JAR), and RFC 9126 (PAR).
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-07T16:26:22.791Z

Reserved: 2025-02-23T00:00:00.000Z

Link: CVE-2025-27371

cve-icon Vulnrichment

Updated: 2025-03-04T16:49:52.914Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-03T18:15:40.850

Modified: 2025-03-07T17:15:22.190

Link: CVE-2025-27371

cve-icon Redhat

No data.