Loading HuntDB...

CVE-2019-12419

UNKNOWN
Published 2019-11-06T20:18:54
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2019-12419. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

✓ GitHub Reviewed CRITICAL

Potential session hijack in Apache CXF

GHSA-cw6w-q88j-6mqf

Advisory Details

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

Affected Packages

Maven org.apache.cxf:cxf
ECOSYSTEM: ≥0 <3.2.11
Maven org.apache.cxf:cxf
ECOSYSTEM: ≥3.3.0 <3.3.4

CVSS Scoring

CVSS Score

9.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Advisory provided by GitHub Security Advisory Database. Published: November 8, 2019, Modified: June 15, 2021

References

Published: 2019-11-06T20:18:54
Last Modified: 2024-08-04T23:17:40.005Z
Copied to clipboard!