Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57817

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 3.7

Описание

The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the c_hash parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the c_hash, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

A flaw was found in Apache CXF. When operating in the OpenID Connect Hybrid Flow, Apache CXF does not enforce the validation of the c_hash parameter. This vulnerability allows a remote attacker, through a non-compliant or misconfigured Identity Provider (IdP), to perform Authorization Code Substitution/Injection attacks. Such an attack could lead to unauthorized access or session hijacking.

Отчет

This vulnerability has a Low impact on Red Hat products. Apache CXF, as used in Red Hat Enterprise Application Platform, Red Hat JBoss Web Server, and Red Hat build of Apache Camel, is susceptible to Authorization Code Substitution/Injection attacks when integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the c_hash parameter in the OpenID Connect Hybrid Flow. Exploitation requires a specific misconfiguration of the external IdP.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4cxfAffected
Red Hat JBoss Web Server 5cxfOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-303
https://bugzilla.redhat.com/show_bug.cgi?id=2511977org.apache.cxf/cxf: Apache CXF: Authorization Code Substitution via missing c_hash validation

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 месяца назад

The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

CVSS3: 9.8
github
около 1 месяца назад

The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

3.7 Low

CVSS3