Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50627

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 8.1

Описание

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

A flaw was found in Apache CXF. The JwtAccessTokenValidator class fails to properly validate the 'aud' (Audience) claims within incoming JSON Web Token (JWT) access tokens. This vulnerability allows an attacker to reuse a JWT, originally intended for one resource server, against a different resource server. This can lead to token confusion and routing attacks, potentially granting unauthorized access or information disclosure.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Important. Although authentication is required (the attacker must possess a valid JWT issued for some resource server), the flaw allows unauthorized access to protected resources on any other resource server using Apache CXF's JwtAccessTokenValidator, enabling full read/write operations across trust boundaries due to the complete absence of audience claim validation in the default configuration.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7cxf-rt-rs-security-oauth2Fix deferred
Red Hat Fuse 7cxf-rt-rs-security-oauth2-samlFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packcxf-rt-rs-security-oauth2Not affected
Red Hat JBoss Enterprise Application Platform Expansion Packcxf-rt-rs-security-oauth2-samlNot affected
Red Hat JBoss Web Server 5cxf-rt-rs-security-oauth2Fix deferred
Red Hat JBoss Web Server 5cxf-rt-rs-security-oauth2-samlFix deferred
Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16cxf-rt-rs-security-oauth2FixedRHSA-2026:3739009.07.2026
Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16cxf-rt-rs-security-oauth2-samlFixedRHSA-2026:3739009.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-303
https://bugzilla.redhat.com/show_bug.cgi?id=2488298apache-cxf: org.apache.cxf/cxf-rt-rs-security-oauth2: Apache CXF: Token Confusion/Routing attacks due to improper validation of JWT audience claims

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
около 2 месяцев назад

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

CVSS3: 9.1
github
около 2 месяцев назад

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

8.1 High

CVSS3