9.4
CVE-2026-55181
- EPSS 0.6%
- Veröffentlicht 30.09.2026 16:57:15
- Zuletzt bearbeitet 30.09.2026 20:17:33
- Erkennungen
Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts the OIDC login flow, returns HTTP 302, sets an oidc_state cookie, and redirects the user to the configured OIDC authorization endpoint. This bypasses the intended OIDC disable switch. This issue has been patched in version 1.30.3.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerQuenary
≫
Produkt
tugtainer
Version
< 1.30.3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.6% | 0.467 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 9.4 | 3.9 | 5.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://github.com/Quenary/tugtainer/security/advisories/GHSA-rg7c-vpfp-2w43
https://github.com/Quenary/tugtainer/commit/76371db679334b002d4af544b0f3b8587ad86f52
https://github.com/Quenary/tugtainer/releases/tag/v1.30.3