Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4956 | Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it. |
Github GHSA |
GHSA-qf8x-vqjv-92gr | Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T18:31:29.148Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24901
Updated: 2024-08-03T04:29:00.957Z
Status : Modified
Published: 2022-05-04T01:15:49.127
Modified: 2024-11-21T06:51:21.370
Link: CVE-2022-24901
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA