{"id":"GHSA-373j-mhpf-84wg","summary":"Janssen Config API returns results without scope verification","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\nThe configAPI is an internal service and hence should never be exposed to the internet. With that said, this is a serious vulnerability that has a large internal surface attack area that exposes all sorts of information from the IDP including clients, users, scripts ..etc.\n\nThis affects all users of Janssen \u003c1.8.0 and Gluu Flex \u003c5.8.0\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\nAll users are advised to upgrade immediately to [1.8.0](https://github.com/JanssenProject/jans/releases/tag/v1.8.0) for Janssen users and [5.8.0](https://github.com/GluuFederation/flex/releases/tag/v5.8.0) For Flex users.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\nThe user can potentially fork and build the config api and patch it in their system following the commit here https://github.com/JanssenProject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1\n\n### References\n_Are there any links users can visit to find out more?_\nhttps://github.com/JanssenProject/jans/issues/11575\nhttps://github.com/JanssenProject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1","aliases":["CVE-2025-53003"],"modified":"2025-07-01T13:13:21Z","published":"2025-06-30T17:52:44Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-06-30T17:52:44Z","nvd_published_at":"2025-07-01T02:15:22Z","cwe_ids":["CWE-200","CWE-269","CWE-284"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/JanssenProject/jans/security/advisories/GHSA-373j-mhpf-84wg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53003"},{"type":"WEB","url":"https://github.com/JanssenProject/jans/issues/11575"},{"type":"WEB","url":"https://github.com/JanssenProject/jans/commit/92eea4d4637f1cae16ad2f07b2c16378ff3fc5f1"},{"type":"WEB","url":"https://github.com/GluuFederation/flex/releases/tag/v5.8.0"},{"type":"PACKAGE","url":"https://github.com/JanssenProject/jans"},{"type":"WEB","url":"https://github.com/JanssenProject/jans/releases/tag/v1.8.0"}],"affected":[{"package":{"name":"io.jans:jans-config-api-server","ecosystem":"Maven","purl":"pkg:maven/io.jans/jans-config-api-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-373j-mhpf-84wg/GHSA-373j-mhpf-84wg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}