Violation of Secure Design Principles, Hidden Functionality, Incorrect Provision of Specified Functionality vulnerability in ArcGIS (Authentication) allows Privilege Abuse, Manipulating Hidden Fields, Configuration/Environment Manipulation.
The ArcGIS client_credentials OAuth 2.0 API implementation does not adhere to the RFC/standards; This hidden (known and by-design, but undocumented) functionality enables a requestor (referred to as client in RFC 6749) to request an, undocumented, custom token expiration from ArcGIS (referred to as authorization server in RFC 6749).
Metrics
Affected Vendors & Products
References
History
Wed, 14 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 14 May 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Violation of Secure Design Principles, Hidden Functionality, Incorrect Provision of Specified Functionality vulnerability in ArcGIS (Authentication) allows Privilege Abuse, Manipulating Hidden Fields, Configuration/Environment Manipulation. The ArcGIS client_credentials OAuth 2.0 API implementation does not adhere to the RFC/standards; This hidden (known and by-design, but undocumented) functionality enables a requestor (Referred to as client in RFC 6749) to request an, undocumented, custom token expiration from ArcGIS (Referred to as authorization server in RFC 6749). | Violation of Secure Design Principles, Hidden Functionality, Incorrect Provision of Specified Functionality vulnerability in ArcGIS (Authentication) allows Privilege Abuse, Manipulating Hidden Fields, Configuration/Environment Manipulation. The ArcGIS client_credentials OAuth 2.0 API implementation does not adhere to the RFC/standards; This hidden (known and by-design, but undocumented) functionality enables a requestor (referred to as client in RFC 6749) to request an, undocumented, custom token expiration from ArcGIS (referred to as authorization server in RFC 6749). |
Wed, 14 May 2025 08:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Violation of Secure Design Principles, Hidden Functionality, Incorrect Provision of Specified Functionality vulnerability in ArcGIS (Authentication) allows Privilege Abuse, Manipulating Hidden Fields, Configuration/Environment Manipulation. The ArcGIS client_credentials OAuth 2.0 API implementation does not adhere to the RFC/standards; This hidden (known and by-design, but undocumented) functionality enables a requestor (Referred to as client in RFC 6749) to request an, undocumented, custom token expiration from ArcGIS (Referred to as authorization server in RFC 6749). | |
Title | ArcGIS Hidden Functionality Allows Insecure OAuth 2.0 Based Authentication | |
Weaknesses | CWE-657 CWE-684 CWE-912 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VULSec
Published: 2025-05-14T07:54:57.843Z
Updated: 2025-05-14T13:20:24.836Z
Reserved: 2024-11-06T08:36:01.058Z
Link: CVE-2025-0020

Updated: 2025-05-14T13:20:20.629Z

Status : Received
Published: 2025-05-14T08:15:33.863
Modified: 2025-05-14T08:15:33.863
Link: CVE-2025-0020

No data.