The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without scope verification. This has a large internal surface attack area that exposes all sorts of information from the IDP including clients, users, scripts ..etc. This issue has been patched in version 1.8.0. A workaround for this vulnerability involves users forking and building the config api, patching it in their system following commit 92eea4d.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-200",
"CWE-269",
"CWE-284"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53003.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53003.json"
"2026-04-12T18:25:22Z"
[
{
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/janssenproject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"276362061651588370579487215925088605143",
"332943949055603677946929577233200608070",
"28310391686919260762271804484458792826"
]
},
"id": "CVE-2025-53003-22b4994d",
"deprecated": false,
"target": {
"file": "jans-config-api/shared/src/main/java/io/jans/configapi/core/test/BaseTest.java"
}
},
{
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/janssenproject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1",
"digest": {
"function_hash": "52450069420073743300468487480741585731",
"length": 2772.0
},
"id": "CVE-2025-53003-2419a1ef",
"deprecated": false,
"target": {
"file": "jans-config-api/server/src/main/java/io/jans/configapi/security/service/OpenIdAuthorizationService.java",
"function": "validateScope"
}
},
{
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/janssenproject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1",
"digest": {
"function_hash": "67254466351227576008653847283337357928",
"length": 290.0
},
"id": "CVE-2025-53003-2544f6d2",
"deprecated": false,
"target": {
"file": "jans-config-api/server/src/main/java/io/jans/configapi/util/AuthUtil.java",
"function": "findMissingElements"
}
},
{
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/janssenproject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"166360489535435235925877251947180666991",
"218222865699742364202574923933090838839",
"291519686411736354682364235175211535459",
"24228752026167720058825227923687351111"
]
},
"id": "CVE-2025-53003-96b14d5b",
"deprecated": false,
"target": {
"file": "jans-config-api/server/src/test/java/io/jans/configapi/test/auth/ClientResourceTest.java"
}
},
{
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/janssenproject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"336686782366867399596860190962833682268",
"293857088454993610366543856631808642228",
"182179468394672153460186480930105761031",
"303680907098592843065749781074156652451",
"249994110523120715948128206323581376187",
"279849968608908240542792643130872484915"
]
},
"id": "CVE-2025-53003-b17b2779",
"deprecated": false,
"target": {
"file": "jans-config-api/server/src/main/java/io/jans/configapi/util/AuthUtil.java"
}
},
{
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/janssenproject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"131182453499737228889024821048031414197",
"283693712514419607530383748606705368391",
"222670911664108903442033271582429409786"
]
},
"id": "CVE-2025-53003-da459a2a",
"deprecated": false,
"target": {
"file": "jans-config-api/server/src/main/java/io/jans/configapi/security/service/OpenIdAuthorizationService.java"
}
}
]