Apache · Apache Cxf · CVE-2017-3156
**Name of the Vulnerable Software and Affected Versions**
Apache CXF versions prior to 3.0.13
Apache CXF versions 3.1.x prior to 3.1.10
**Description**
The issue concerns the OAuth2 Hawk and JOSE MAC Validation code, which does not utilize a constant time MAC signature comparison algorithm. This could potentially be exploited by sophisticated timing attacks.
**Recommendations**
For Apache CXF versions prior to 3.0.13, update to version 3.0.13 or later.
For Apache CXF versions 3.1.x prior to 3.1.10, update to version 3.1.10 or later.