org.apache.cxf:cxf-rt-rs-security-oauth2@3.0.0-milestone2 vulnerabilities

  • latest version

    4.1.2

  • latest non vulnerable version

  • first published

    13 years ago

  • latest version published

    1 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.cxf:cxf-rt-rs-security-oauth2 package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Denial of Service (DoS)

    org.apache.cxf:cxf-rt-rs-security-oauth2 is a services framework.

    Affected versions of this package are vulnerable to Denial of Service (DoS). It allows attacks on the authorization server, due to lack of validation of the request_uri parameter.

    How to fix Denial of Service (DoS)?

    Upgrade org.apache.cxf:cxf-rt-rs-security-oauth2 to version 3.3.10, 3.4.3 or higher.

    [,3.3.10)[3.4.0,3.4.3)
    • H
    Timing Attack

    org.apache.cxf:cxf-rt-rs-security-oauth2 is a services framework.

    Affected versions of this package are vulnerable to Timing Attack because it does not use a constant time MAC signature comparison algorithm.

    How to fix Timing Attack?

    Upgrade org.apache.cxf:cxf-rt-rs-security-oauth2 to version 3.0.13, 3.1.10 or higher.

    [,3.0.13)[3.1.0,3.1.10)