Back

HIGH

cxf: CXF OAuth2 Hawk and JOSE MAC Validation code are vulnerable to timing attacks

Published Aug 10, 2017

Description

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Aug 10, 2017
Updated Sep 16, 2024
Reserved Dec 5, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 20, 2017
GHSA-QC2P-Q7X9-V64P