Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v936-x3j5-c76j

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Session Fixation in Apache CXF

Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.

Пакеты

Наименование

org.apache.cxf:cxf-core

maven
Затронутые версииВерсия исправления

>= 3.1.0, <= 3.1.10

3.1.11

Наименование

org.apache.cxf:cxf-core

maven
Затронутые версииВерсия исправления

<= 3.0.12

3.0.13

EPSS

Процентиль: 88%
0.03801
Низкий

7.5 High

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 5.3
redhat
почти 9 лет назад

Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.

CVSS3: 7.5
nvd
почти 9 лет назад

Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.

EPSS

Процентиль: 88%
0.03801
Низкий

7.5 High

CVSS3

Дефекты

CWE-384