Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows clients to be created, deleted, etc. A CSRF (Cross Style Request Forgery) style vulnerability has been found in this web application in Apache CXF Fediz prior to 1.4.0 and 1.3.2, meaning that a malicious web application could create new clients, or reset secrets, etc, after the admin user has logged on to the client registration service and the session is still active.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3693 | Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows clients to be created, deleted, etc. A CSRF (Cross Style Request Forgery) style vulnerability has been found in this web application in Apache CXF Fediz prior to 1.4.0 and 1.3.2, meaning that a malicious web application could create new clients, or reset secrets, etc, after the admin user has logged on to the client registration service and the session is still active. |
Github GHSA |
GHSA-f5ch-36rg-vfcc | Cross-Site Request Forgery in Apache CXF Fediz |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T16:12:27.730Z
Reserved: 2017-04-11T00:00:00
Link: CVE-2017-7662
No data.
Status : Deferred
Published: 2017-05-16T17:29:00.497
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-7662
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA