CyberRota Analysis
AI-GeneratedAn authentication bypass vulnerability in pac4j-core versions prior to 6.5.6 allows attackers to exploit reversed profile type validation in the CheckProfileTypeAuthorizer, enabling them to gain unauthorized access to resources that require a stronger profile type. This issue poses a significant risk to applications relying on pac4j for authentication, particularly those managing sensitive user data. Organizations utilizing affected versions should prioritize immediate updates to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks.