Логотип exploitDog
bind:CVE-2019-12419
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-12419

Количество 4

Количество 4

redhat логотип

CVE-2019-12419

больше 6 лет назад

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

CVSS3: 8.1
EPSS: Средний
nvd логотип

CVE-2019-12419

больше 6 лет назад

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-cw6w-q88j-6mqf

больше 6 лет назад

Potential session hijack in Apache CXF

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2020-00858

около 6 лет назад

Уязвимость службы OpenId Connect каркаса для веб-сервисов Apache CXF, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2019-12419

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

CVSS3: 8.1
18%
Средний
больше 6 лет назад
nvd логотип
CVE-2019-12419

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

CVSS3: 9.8
18%
Средний
больше 6 лет назад
github логотип
GHSA-cw6w-q88j-6mqf

Potential session hijack in Apache CXF

CVSS3: 9.8
18%
Средний
больше 6 лет назад
fstec логотип
BDU:2020-00858

Уязвимость службы OpenId Connect каркаса для веб-сервисов Apache CXF, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.8
18%
Средний
около 6 лет назад

Уязвимостей на страницу