CyberRota Analysis
AI-GeneratedA vulnerability exists in the StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange, affecting Exchange products. The flaw arises from the use of unanchored regular expressions in role mappings, allowing an attacker with a valid OpenID Connect (OIDC) token to exploit claim values and gain unauthorized access to elevated roles, potentially leading to privilege escalation. Organizations utilizing this system should prioritize remediation to mitigate the risk of unauthorized access and maintain security integrity.
Original NVD Description
A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value is a superstring of a configured pattern, to gain unauthorized access to roles they were not intended to receive. This can lead to privilege escalation within the system.