Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5656

Опубликовано: 05 апр. 2017
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.

It was found that the token cacher in Apache cxf uses a flawed way of caching tokens that are associated with the delegation token received from Security Token Service (STS). This vulnerability could allow an attacker to craft a token which could return an identifier corresponding to a cached token for another user.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6cxfNot affected
Red Hat JBoss BRMS 5cxfNot affected
Red Hat JBoss BRMS 6cxfNot affected
Red Hat JBoss Data Grid 6cxfNot affected
Red Hat JBoss Data Virtualization 6cxfNot affected
Red Hat JBoss Enterprise Application Platform 5cxfNot affected
Red Hat JBoss Enterprise Application Platform 6cxfNot affected
Red Hat JBoss Fuse Service Works 6cxfNot affected
Red Hat JBoss Operations Network 3cxfNot affected
Red Hat JBoss Portal 6cxfNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1445329cxf: CXF's STSClient uses a flawed way of caching tokens that are associated with delegation tokens

EPSS

Процентиль: 88%
0.03801
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 9 лет назад

Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.

CVSS3: 7.5
github
больше 3 лет назад

Session Fixation in Apache CXF

EPSS

Процентиль: 88%
0.03801
Низкий

5.3 Medium

CVSS3