PT-2017-16650 · Apache · Apache Cxf

Publicado

2017-04-18

·

Atualizado

2022-05-13

·

CVE-2017-5656

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache CXF versions prior to 3.1.11 Apache CXF versions prior to 3.0.13
Description The issue is related to a flawed token caching mechanism in the STSClient, allowing an attacker to craft a token that could return an identifier corresponding to a cached token for another user.
Recommendations For Apache CXF versions prior to 3.1.11, update to version 3.1.11 or later. For Apache CXF versions prior to 3.0.13, update to version 3.0.13 or later.

Correção

Session Fixation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-5656
GHSA-V936-X3J5-C76J

Produtos afetados

Apache Cxf