4.2.1
14 years ago
1 months ago
Known vulnerabilities in the org.apache.cxf:cxf-rt-rs-security-oauth2 package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.apache.cxf:cxf-rt-rs-security-oauth2 is a services framework. Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition due to a race condition in the How to fix Time-of-check Time-of-use (TOCTOU) Race Condition? Upgrade | [,4.1.7)[4.2.0,4.2.2) |
org.apache.cxf:cxf-rt-rs-security-oauth2 is a services framework. Affected versions of this package are vulnerable to HTTP Response Splitting via improper handling of the How to fix HTTP Response Splitting? Upgrade | [,4.1.7)[4.2.0,4.2.2) |
org.apache.cxf:cxf-rt-rs-security-oauth2 is a services framework. Affected versions of this package are vulnerable to Authentication Bypass by Alternate Name via the How to fix Authentication Bypass by Alternate Name? Upgrade | [,4.1.7)[4.2.0,4.2.2) |
org.apache.cxf:cxf-rt-rs-security-oauth2 is a services framework. Affected versions of this package are vulnerable to Missing Authentication for Critical Function due to a missing 'throw' keyword in the security context check within the How to fix Missing Authentication for Critical Function? Upgrade | [,4.1.7)[4.2.0,4.2.2) |
org.apache.cxf:cxf-rt-rs-security-oauth2 is a services framework. Affected versions of this package are vulnerable to CRLF Injection via the How to fix CRLF Injection? Upgrade | [,4.1.7)[4.2.0,4.2.2) |
org.apache.cxf:cxf-rt-rs-security-oauth2 is a services framework. Affected versions of this package are vulnerable to Improperly Implemented Security Check for Standard due to a logic error in the How to fix Improperly Implemented Security Check for Standard? Upgrade | [,4.1.7)[4.2.0,4.2.2) |