Impact
The vulnerability in Apache CXF’s JPA OAuth2 authorization code grant provider permits a remote attacker to obtain multiple distinct access tokens from a single authorization code. The flaw arises from a race condition between a non‑atomic find and delete operation that targets a shared relational database operating under READ_COMMITTED isolation. Because the provider incorrectly permits concurrent token exchanges, the single‑use constraint is violated, allowing the attacker to replay the code and gain unauthorized access to protected resources. The issue is a classic example of flawed atomicity and concurrency control (CWE‑367).
Affected Systems
Apache Software Foundation’s Apache CXF is impacted. Versions older than 4.2.4, 4.1.9, or 3.6.13 lack the fix and therefore are vulnerable. No other vendors or products are listed as affected in this advisory.
Risk and Exploitability
The CVSS score and EPSS are not provided, and the vulnerability is not listed in the CISA KEV catalog, so an official severity assessment is unavailable. Nevertheless, the exploit requires only concurrent HTTP requests to the token exchange endpoint and no special privileges beyond those needed to initiate a token request. Any client capable of sending such requests can generate an unlimited number of tokens until administrative limits or logs trigger suspicion. The absence of an EPSS rating suggests that exploitation may not yet have been observed in the wild, but the design flaw presents a high risk for credential misuse and should be treated as significant.
OpenCVE Enrichment