Impact
The flaw occurs when the backend module decodes the OIDC id_token using a function that skips all cryptographic and claim validation, allowing an attacker to supply a forged token. The extracted claims are trusted as the user identity, enabling the attacker to obtain a Tugtainer session with the permissions of the targeted account. This bypasses authentication and can be used to elevate privileges within the application.
Affected Systems
The vulnerability affects the Quenary Tugtainer self‑hosted automation tool, specifically versions earlier than 1.31.3. An attacker could target any deployment of these affected releases that uses OIDC for authentication.
Risk and Exploitability
With a CVSS score of 8.1, the vulnerability is classified as high severity. Although no EPSS data is available, the lack of signature and claim validation creates a straightforward exploitation path: an attacker crafts a valid‑looking token, initiates an OIDC login, and receives a privileged session. The issue is not listed in CISA KEV, but the impact remains significant for organizations relying on the affected application.
OpenCVE Enrichment