Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0034

Опубликовано: 01 мая 2014
Источник: redhat
CVSS2: 4.3

Описание

The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.

It was found that the SecurityTokenService (STS), provided as a part of Apache CXF, could under certain circumstances accept invalid SAML tokens as valid. A remote attacker could use a specially crafted SAML token to gain access to an application that uses STS for validation of SAML tokens.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1cxfWill not fix
Red Hat BPM Suite 6cxfAffected
Red Hat JBoss BRMS 5cxfWill not fix
Red Hat JBoss BRMS 6cxfAffected
Red Hat JBoss Enterprise Web Server 1amq-6.1Affected
Red Hat JBoss Enterprise Web Server 1fuse-6.1Affected
Red Hat JBoss Fuse Service Works 6cxfAffected
Red Hat JBoss Portal 6cxfAffected
Red Hat OpenShift Enterprise 2cxfWill not fix
Red Hat JBoss A-MQ 6.1FixedRHSA-2014:135101.10.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=1093529CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.

github
больше 3 лет назад

Improper Input Validation in Apache CXF

4.3 Medium

CVSS2