org.apache.cxf:cxf-rt-rs-security-sso-oidc@4.0.10

  • latest version

    4.2.3

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    1 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.cxf:cxf-rt-rs-security-sso-oidc package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Insufficient Verification of Data Authenticity

    org.apache.cxf:cxf-rt-rs-security-sso-oidc is an Apache CXF Runtime OpenId Connect library.

    Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity in the OIDC relying-party token validation process. An attacker can bypass authentication by submitting crafted self-issued ID tokens that are not properly validated for required claims such as issuer, subject, audience, time, and sub_jwk binding. This is only exploitable if self-issued ID tokens are explicitly accepted in the validator configuration.

    How to fix Insufficient Verification of Data Authenticity?

    Upgrade org.apache.cxf:cxf-rt-rs-security-sso-oidc to version 3.6.12, 4.1.8, 4.2.3 or higher.

    [,3.6.12)[4.0.0,4.1.8)[4.2.0,4.2.3)
    • C
    Improper Verification of Cryptographic Signature

    org.apache.cxf:cxf-rt-rs-security-sso-oidc is an Apache CXF Runtime OpenId Connect library.

    Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature in the OpenID Connect Hybrid Flow when the c_hash parameter is not validated. An attacker can substitute or inject an authorization code by exploiting the lack of enforcement of the c_hash parameter when integrated with a non-compliant or misconfigured Identity Provider (IdP). This is only exploitable if the Identity Provider omits the c_hash parameter in the Hybrid Flow.

    How to fix Improper Verification of Cryptographic Signature?

    Upgrade org.apache.cxf:cxf-rt-rs-security-sso-oidc to version 3.6.12, 4.1.8, 4.2.3 or higher.

    [,3.6.12)[4.0.0,4.1.8)[4.2.0,4.2.3)