Due to a permissive regular expression hardcoded for filtering allowed hosts to register a dynamic client, a malicious user with enough information about the environment could benefit and jeopardize an environment with this specific Dynamic Client Registration with TrustedDomain configuration previously unauthorized.
Special thanks to Bastian Kanbach for reporting this issue and helping us improve our security.
{ "nvd_published_at": "2024-04-25T16:15:10Z", "cwe_ids": [ "CWE-625" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-04-17T17:33:29Z" }