Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[JBEAP-26098] CVE-2023-6236 wildfly: JBoss EAP: OIDC app attempting to access the second tenant, the user should be prompted to log #2130

Merged
merged 2 commits into from
Apr 22, 2024

Commits on Apr 18, 2024

  1. [JBEAP-26097] CVE-2023-6236: Compare the provider-url for a cached ac…

    …count against the provider-url required for a request to determine if a cached token can be used
    fjuma authored and ivassile committed Apr 18, 2024
    Configuration menu
    Copy the full SHA
    79d523d View commit details
    Browse the repository at this point in the history
  2. [JBEAP-26097] CVE-2023-6236: Add tests for multi-tenancy to ensure that

    a valid token from one tenant cannot be used to access another tenant
    fjuma authored and ivassile committed Apr 18, 2024
    Configuration menu
    Copy the full SHA
    6ac02f3 View commit details
    Browse the repository at this point in the history