Impact
The vulnerability originates in Apache CXF’s OIDC relying‑party component, where attacker‑controlled state parameters are later used to construct a redirect target without validating the final decoded URI. After a successful authentication, the application can redirect a user to an arbitrary external URL, potentially leading to phishing or credential theft. The flaw is a classic open‑redirect issue, not a code execution vector, but it enables an attacker to influence user navigation and trust context.
Affected Systems
The affected product is Apache CXF, specifically the OIDC relying‑party component. Versions preceding 4.2.4, 4.1.9, and 3.6.13 contain the flaw. Users running these releases are at risk until they upgrade.
Risk and Exploitability
No EPSS data is available and the vulnerability is not listed in CISA KEV, indicating limited public exploitation evidence. However, the CVE description warns that both directly and double‑encoded URLs can trigger the redirect, suggesting that the attack vector is straightforward once the attacker can supply a state parameter. The issue is considered high impact because it can facilitate phishing attacks post-authentication, and the fixed releases provide a straightforward remediation path.
OpenCVE Enrichment