Описание
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
A flaw was found in Apache CXF. The JwtAccessTokenValidator class fails to properly validate the 'aud' (Audience) claims within incoming JSON Web Token (JWT) access tokens. This vulnerability allows an attacker to reuse a JWT, originally intended for one resource server, against a different resource server. This can lead to token confusion and routing attacks, potentially granting unauthorized access or information disclosure.
Отчет
The Red Hat Product Security team has assessed the severity of this vulnerability as Important. Although authentication is required (the attacker must possess a valid JWT issued for some resource server), the flaw allows unauthorized access to protected resources on any other resource server using Apache CXF's JwtAccessTokenValidator, enabling full read/write operations across trust boundaries due to the complete absence of audience claim validation in the default configuration.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | cxf-rt-rs-security-oauth2 | Fix deferred | ||
| Red Hat Fuse 7 | cxf-rt-rs-security-oauth2-saml | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | cxf-rt-rs-security-oauth2 | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | cxf-rt-rs-security-oauth2-saml | Not affected | ||
| Red Hat JBoss Web Server 5 | cxf-rt-rs-security-oauth2 | Fix deferred | ||
| Red Hat JBoss Web Server 5 | cxf-rt-rs-security-oauth2-saml | Fix deferred | ||
| Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16 | cxf-rt-rs-security-oauth2 | Fixed | RHSA-2026:37390 | 09.07.2026 |
| Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16 | cxf-rt-rs-security-oauth2-saml | Fixed | RHSA-2026:37390 | 09.07.2026 |
Показывать по
Дополнительная информация
Статус:
8.1 High
CVSS3
Связанные уязвимости
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
8.1 High
CVSS3