Описание
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the c_hash parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the c_hash, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
A flaw was found in Apache CXF. When operating in the OpenID Connect Hybrid Flow, Apache CXF does not enforce the validation of the c_hash parameter. This vulnerability allows a remote attacker, through a non-compliant or misconfigured Identity Provider (IdP), to perform Authorization Code Substitution/Injection attacks. Such an attack could lead to unauthorized access or session hijacking.
Отчет
This vulnerability has a Low impact on Red Hat products. Apache CXF, as used in Red Hat Enterprise Application Platform, Red Hat JBoss Web Server, and Red Hat build of Apache Camel, is susceptible to Authorization Code Substitution/Injection attacks when integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the c_hash parameter in the OpenID Connect Hybrid Flow. Exploitation requires a specific misconfiguration of the external IdP.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel for Spring Boot 4 | cxf | Affected | ||
| Red Hat JBoss Web Server 5 | cxf | Out of support scope |
Показывать по
Дополнительная информация
Статус:
3.7 Low
CVSS3
Связанные уязвимости
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
3.7 Low
CVSS3