Back

HIGH

Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter

Published May 4, 2022

Description

Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 4, 2022
Updated Apr 23, 2025
Reserved Feb 10, 2022
CISA Vulnrichment
Updated Apr 23, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published May 4, 2022
Updated Apr 23, 2025
Exploited since n/a
EUVD-2022-4956 GHSA-QF8X-VQJV-92GR