kanidm
Activity
- Latest release
- 6y ago
- Total releases
- 3
- Cadence
- ~3 months
- Last 12 months
- 0
Details
- License
- MPL-2.0
- First release
- Dec 17, 2019
| Version | Released | |
|---|---|---|
1.1.0-alpha
unknown
2 CVEs
GHSA-53hj-r94p-8c8f
May 06, 2026
Kanidm has non-constant-time comparison of OAuth2 client_secret
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThe kanidmd OAuth2 token-exchange ( Details
PoCStatic analysis only — no timing-recovery script was run because remote recovery of a 48-byte high-entropy secret over HTTPS is not practically demonstrable. The variable-time behaviour is established by inspection:
ImpactAn unauthenticated network attacker who can reach the OAuth2 endpoints can submit arbitrary Affected versionsAll published Fixed in
1.9.3
References Updated May 06, 2026 · Source: OSV.dev
GHSA-gpxg-fx2g-qxj2
May 06, 2026
Kanidm: Stored HTML injection in "passkey-enrolment" partial via displayname → htmx-driven authenticated request forgery
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryThe kanidmd web UI renders the WebAuthn passkey-registration challenge as raw JSON inside an inline ImpactAn authenticated attacker who is a member of Details
Affected versionsAll releases shipping the htmx credential-update views Fixed in
1.9.3
References Updated May 06, 2026 · Source: OSV.dev |
1.1.0-alpha
unknown
Dependencies (42)
+ 34 more |
|
0.1.1
unknown
2 CVEs
GHSA-53hj-r94p-8c8f
May 06, 2026
Kanidm has non-constant-time comparison of OAuth2 client_secret
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThe kanidmd OAuth2 token-exchange ( Details
PoCStatic analysis only — no timing-recovery script was run because remote recovery of a 48-byte high-entropy secret over HTTPS is not practically demonstrable. The variable-time behaviour is established by inspection:
ImpactAn unauthenticated network attacker who can reach the OAuth2 endpoints can submit arbitrary Affected versionsAll published Fixed in
1.9.3
References Updated May 06, 2026 · Source: OSV.dev
GHSA-gpxg-fx2g-qxj2
May 06, 2026
Kanidm: Stored HTML injection in "passkey-enrolment" partial via displayname → htmx-driven authenticated request forgery
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryThe kanidmd web UI renders the WebAuthn passkey-registration challenge as raw JSON inside an inline ImpactAn authenticated attacker who is a member of Details
Affected versionsAll releases shipping the htmx credential-update views Fixed in
1.9.3
References Updated May 06, 2026 · Source: OSV.dev |
0.1.1
unknown
Dependencies (32)
+ 24 more |
|
0.1.0
unknown
2 CVEs
GHSA-53hj-r94p-8c8f
May 06, 2026
Kanidm has non-constant-time comparison of OAuth2 client_secret
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThe kanidmd OAuth2 token-exchange ( Details
PoCStatic analysis only — no timing-recovery script was run because remote recovery of a 48-byte high-entropy secret over HTTPS is not practically demonstrable. The variable-time behaviour is established by inspection:
ImpactAn unauthenticated network attacker who can reach the OAuth2 endpoints can submit arbitrary Affected versionsAll published Fixed in
1.9.3
References Updated May 06, 2026 · Source: OSV.dev
GHSA-gpxg-fx2g-qxj2
May 06, 2026
Kanidm: Stored HTML injection in "passkey-enrolment" partial via displayname → htmx-driven authenticated request forgery
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryThe kanidmd web UI renders the WebAuthn passkey-registration challenge as raw JSON inside an inline ImpactAn authenticated attacker who is a member of Details
Affected versionsAll releases shipping the htmx credential-update views Fixed in
1.9.3
References Updated May 06, 2026 · Source: OSV.dev |
0.1.0
unknown
Dependencies (31)
+ 23 more |