laptop and a wrench

漏洞

Generating a token using the OAuth2.0 endpoints with a valid Client ID and Client Secret returns a token, which is not valid to access services, which are owned by the same user who created the registered application. This occurs in a federated Portal for ArcGIS and ArcGIS GIS Server environment with a hosting server configured.

上次发布: March 1, 2016 ArcGIS API for JavaScript
漏洞 ID 编号 BUG-000093367
已提交January 7, 2016
上次修改时间June 5, 2024
适用范围ArcGIS API for JavaScript
找到的版本3.14
操作系统Windows OS
操作系统版本7.0 64 Bit
状态Will Not Be Addressed

附加信息

This is intended behavior, it is a limitation of app logins. Tokens obtained by applications can only read public content and services. Although an App login cannot be used with private content, if the goal is to distribute or sell an app to organizations without ArcGIS Online (no named users), the control access to the content may be controlled by using an login mechanism (Identity) to the app. https://developers.arcgis.com/documentation/core-concepts/security-and-authentication/limitations-of-application-authentication/

重现步骤

漏洞 ID: BUG-000093367

软件:

  • ArcGIS API for JavaScript

当漏洞状态发生变化时获得通知

下载 Esri 支持应用程序

发现关于本主题的更多内容

获取来自 ArcGIS 专家的帮助

联系技术支持部门

下载 Esri 支持应用程序

转至下载选项