CVE-2025-53003

Source
https://cve.org/CVERecord?id=CVE-2025-53003
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53003.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-53003
Aliases
Published
2025-07-01T01:22:05.855Z
Modified
2026-04-12T18:25:22.275212Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Janssen Config API returns results without scope verification
Details

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without scope verification. This has a large internal surface attack area that exposes all sorts of information from the IDP including clients, users, scripts ..etc. This issue has been patched in version 1.8.0. A workaround for this vulnerability involves users forking and building the config api, patching it in their system following commit 92eea4d.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200",
        "CWE-269",
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53003.json"
}
References

Affected packages

Git / github.com/janssenproject/jans

Affected ranges

Type
GIT
Repo
https://github.com/janssenproject/jans
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/janssenproject/jans
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*
1.0.0-a3
1.0.0-a4
charts-v1.*
charts-v1.0.0-beta.14
docker-jans-auth-server-v1.*
docker-jans-auth-server-v1.0.0-beta.13
docker-jans-auth-server-v1.0.0-beta.14
docker-jans-auth-server-v1.0.0-beta.15
docker-jans-auth-server-v1.0.0-beta.16
docker-jans-certmanager-v1.*
docker-jans-certmanager-v1.0.0-beta.13
docker-jans-certmanager-v1.0.0-beta.14
docker-jans-certmanager-v1.0.0-beta.15
docker-jans-certmanager-v1.0.0-beta.16
docker-jans-client-api-v1.*
docker-jans-client-api-v1.0.0-beta.13
docker-jans-client-api-v1.0.0-beta.14
docker-jans-client-api-v1.0.0-beta.15
docker-jans-client-api-v1.0.0-beta.16
docker-jans-config-api-v1.*
docker-jans-config-api-v1.0.0-beta.13
docker-jans-config-api-v1.0.0-beta.14
docker-jans-config-api-v1.0.0-beta.15
docker-jans-config-api-v1.0.0-beta.16
docker-jans-configurator-v1.*
docker-jans-configurator-v1.0.0-beta.13
docker-jans-configurator-v1.0.0-beta.14
docker-jans-configurator-v1.0.0-beta.15
docker-jans-configurator-v1.0.0-beta.16
docker-jans-fido2-v1.*
docker-jans-fido2-v1.0.0-beta.13
docker-jans-fido2-v1.0.0-beta.14
docker-jans-fido2-v1.0.0-beta.15
docker-jans-fido2-v1.0.0-beta.16
docker-jans-persistence-loader-v1.*
docker-jans-persistence-loader-v1.0.0-beta.13
docker-jans-persistence-loader-v1.0.0-beta.14
docker-jans-persistence-loader-v1.0.0-beta.15
docker-jans-persistence-loader-v1.0.0-beta.16
docker-jans-scim-v1.*
docker-jans-scim-v1.0.0-beta.13
docker-jans-scim-v1.0.0-beta.14
docker-jans-scim-v1.0.0-beta.15
docker-jans-scim-v1.0.0-beta.16
docs-v1.*
docs-v1.0.0-beta.15
docs-v1.0.0-beta.16
jans-auth-server-v1.*
jans-auth-server-v1.0.0-beta.15
jans-auth-server-v1.0.0-beta.16
jans-bom-v1.*
jans-bom-v1.0.0-beta.15
jans-bom-v1.0.0-beta.16
jans-cli-v1.*
jans-cli-v1.0.0-beta.15
jans-cli-v1.0.0-beta.16
jans-client-api-v1.*
jans-client-api-v1.0.0-beta.15
jans-client-api-v1.0.0-beta.16
jans-config-api-v1.*
jans-config-api-v1.0.0-beta.15
jans-config-api-v1.0.0-beta.16
jans-core-v1.*
jans-core-v1.0.0-beta.15
jans-core-v1.0.0-beta.16
jans-eleven-v1.*
jans-eleven-v1.0.0-beta.15
jans-eleven-v1.0.0-beta.16
jans-fido2-v1.*
jans-fido2-v1.0.0-beta.15
jans-fido2-v1.0.0-beta.16
jans-linux-setup-v1.*
jans-linux-setup-v1.0.0-beta.15
jans-linux-setup-v1.0.0-beta.16
jans-notify-v1.*
jans-notify-v1.0.0-beta.15
jans-notify-v1.0.0-beta.16
jans-orm-v1.*
jans-orm-v1.0.0-beta.15
jans-orm-v1.0.0-beta.16
jans-pycloudlib-v1.*
jans-pycloudlib-v1.0.0-beta.13
jans-pycloudlib-v1.0.0-beta.14
jans-pycloudlib-v1.0.0-beta.15
jans-pycloudlib-v1.0.0-beta.16
jans-scim-v1.*
jans-scim-v1.0.0-beta.15
jans-scim-v1.0.0-beta.16
v1.*
v1.0.0-a1
v1.0.0-a2
v1.0.0-beta.15
v1.0.0-beta.16
v1.1.6
v1.2.0
v1.3.0
v1.4.0
v1.5.0
v1.6.0
v1.7.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53003.json"
vanir_signatures_modified
"2026-04-12T18:25:22Z"
vanir_signatures
[
    {
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/janssenproject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "276362061651588370579487215925088605143",
                "332943949055603677946929577233200608070",
                "28310391686919260762271804484458792826"
            ]
        },
        "id": "CVE-2025-53003-22b4994d",
        "deprecated": false,
        "target": {
            "file": "jans-config-api/shared/src/main/java/io/jans/configapi/core/test/BaseTest.java"
        }
    },
    {
        "signature_version": "v1",
        "signature_type": "Function",
        "source": "https://github.com/janssenproject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1",
        "digest": {
            "function_hash": "52450069420073743300468487480741585731",
            "length": 2772.0
        },
        "id": "CVE-2025-53003-2419a1ef",
        "deprecated": false,
        "target": {
            "file": "jans-config-api/server/src/main/java/io/jans/configapi/security/service/OpenIdAuthorizationService.java",
            "function": "validateScope"
        }
    },
    {
        "signature_version": "v1",
        "signature_type": "Function",
        "source": "https://github.com/janssenproject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1",
        "digest": {
            "function_hash": "67254466351227576008653847283337357928",
            "length": 290.0
        },
        "id": "CVE-2025-53003-2544f6d2",
        "deprecated": false,
        "target": {
            "file": "jans-config-api/server/src/main/java/io/jans/configapi/util/AuthUtil.java",
            "function": "findMissingElements"
        }
    },
    {
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/janssenproject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "166360489535435235925877251947180666991",
                "218222865699742364202574923933090838839",
                "291519686411736354682364235175211535459",
                "24228752026167720058825227923687351111"
            ]
        },
        "id": "CVE-2025-53003-96b14d5b",
        "deprecated": false,
        "target": {
            "file": "jans-config-api/server/src/test/java/io/jans/configapi/test/auth/ClientResourceTest.java"
        }
    },
    {
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/janssenproject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "336686782366867399596860190962833682268",
                "293857088454993610366543856631808642228",
                "182179468394672153460186480930105761031",
                "303680907098592843065749781074156652451",
                "249994110523120715948128206323581376187",
                "279849968608908240542792643130872484915"
            ]
        },
        "id": "CVE-2025-53003-b17b2779",
        "deprecated": false,
        "target": {
            "file": "jans-config-api/server/src/main/java/io/jans/configapi/util/AuthUtil.java"
        }
    },
    {
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/janssenproject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "131182453499737228889024821048031414197",
                "283693712514419607530383748606705368391",
                "222670911664108903442033271582429409786"
            ]
        },
        "id": "CVE-2025-53003-da459a2a",
        "deprecated": false,
        "target": {
            "file": "jans-config-api/server/src/main/java/io/jans/configapi/security/service/OpenIdAuthorizationService.java"
        }
    }
]