Description
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cw6w-q88j-6mqf | Potential session hijack in Apache CXF |
References
History
No history.
Subscriptions
Apache
Subscribe
Cxf
Subscribe
Oracle
Subscribe
Commerce Guided Search
Subscribe
Enterprise Manager Base Platform
Subscribe
Flexcube Private Banking
Subscribe
Retail Order Broker
Subscribe
Redhat
Subscribe
Jboss Enterprise Application Platform Cd
Subscribe
Jboss Fuse
Subscribe
Openshift Application Runtimes
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T23:17:40.005Z
Reserved: 2019-05-28T00:00:00.000Z
Link: CVE-2019-12419
No data.
Status : Modified
Published: 2019-11-06T21:15:11.243
Modified: 2024-11-21T04:22:48.197
Link: CVE-2019-12419
OpenCVE Enrichment
No data.
Github GHSA