4.2.3
11 years ago
1 months ago
Known vulnerabilities in the org.apache.cxf:cxf-rt-rs-security-sso-oidc package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.apache.cxf:cxf-rt-rs-security-sso-oidc is an Apache CXF Runtime OpenId Connect library. Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity in the OIDC relying-party token validation process. An attacker can bypass authentication by submitting crafted self-issued ID tokens that are not properly validated for required claims such as issuer, subject, audience, time, and sub_jwk binding. This is only exploitable if self-issued ID tokens are explicitly accepted in the validator configuration. How to fix Insufficient Verification of Data Authenticity? Upgrade | [,3.6.12)[4.0.0,4.1.8)[4.2.0,4.2.3) |
org.apache.cxf:cxf-rt-rs-security-sso-oidc is an Apache CXF Runtime OpenId Connect library. Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature in the OpenID Connect Hybrid Flow when the How to fix Improper Verification of Cryptographic Signature? Upgrade | [,3.6.12)[4.0.0,4.1.8)[4.2.0,4.2.3) |