cxf: OpenId Connect token service does not properly validate the clientId
Published Nov 6, 2019
9.8
CRITICALCVSS 3.1
EPSS 13.84%
Description
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.
Affected products
-
- Version versions before 3.3.4 and 3.2.11StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache | Apache CXF | n/a |
|
Configuration 1
Configuration 2
- 11.3.2
- 13.2.1.0
- 12.0.0
- 12.1.0
- 15.0
No data.
EAP-CD 19 Tech Preview
cxf-core
Fixed · RHSA-2020:2333
Red Hat Fuse 7.7.0
n/a
Fixed · RHSA-2020:3192
Text-Only RHOAR
n/a
Fixed · RHSA-2020:2067
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch6-rhel8
Not affected
Red Hat BPM Suite 6
cxf
Out of support scope
Red Hat BPM Suite 6
cxf-core
Out of support scope
Red Hat Decision Manager 7
cxf-core
Not affected
Red Hat Fuse 7
cxf-core
Affected
Red Hat JBoss BRMS 6
cxf
Out of support scope
Red Hat JBoss BRMS 6
cxf-core
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
cxf-core
Not affected
Red Hat JBoss Fuse 6
cxf-core
Out of support scope
Red Hat OpenShift Application Runtimes
cxf-core
Affected
Red Hat Process Automation 7
cxf-core
Not affected
Red Hat Single Sign-On 7
cxf-core
Not affected
Red Hat support for Spring Boot
cxf-core
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| EAP-CD 19 Tech Preview | cxf-core | Fixed | RHSA-2020:2333 |
| Red Hat Fuse 7.7.0 | n/a | Fixed | RHSA-2020:3192 |
| Text-Only RHOAR | n/a | Fixed | RHSA-2020:2067 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel8 | Not affected | n/a |
| Red Hat BPM Suite 6 | cxf | Out of support scope | n/a |
| Red Hat BPM Suite 6 | cxf-core | Out of support scope | n/a |
| Red Hat Decision Manager 7 | cxf-core | Not affected | n/a |
| Red Hat Fuse 7 | cxf-core | Affected | n/a |
| Red Hat JBoss BRMS 6 | cxf | Out of support scope | n/a |
| Red Hat JBoss BRMS 6 | cxf-core | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | cxf-core | Not affected | n/a |
| Red Hat JBoss Fuse 6 | cxf-core | Out of support scope | n/a |
| Red Hat OpenShift Application Runtimes | cxf-core | Affected | n/a |
| Red Hat Process Automation 7 | cxf-core | Not affected | n/a |
| Red Hat Single Sign-On 7 | cxf-core | Not affected | n/a |
| Red Hat support for Spring Boot | cxf-core | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
In OpenShift Logging the openshift-logging/elasticsearch6-rhel8 container bundles the vulnerable version of apache-cxf, but the vulnerable class is not shipped, hence this component is not affected by this vulnerability.
References (29)
- http://cxf.apache.org/security-advisories.data/CVE-2019-12419.txt.asc x_refsource_CONFIRMVendor Advisory
- https://access.redhat.com/security/cve/CVE-2019-12419 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1816175 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0745 Advisory
- https://github.com/advisories/GHSA-cw6w-q88j-6mqf Advisory
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/r861eb1a9e0250e9150215b17f0263edf62becd5e20fc96251cff59f6%40%3Cdev.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r861eb1a9e0250e9150215b17f0263edf62becd5e20fc96251cff59f6@%3Cdev.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/re7593a274ee0a85d304d5d42c66fc0081c94d7f22bc96a1084d43b80%40%3Cdev.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/re7593a274ee0a85d304d5d42c66fc0081c94d7f22bc96a1084d43b80@%3Cdev.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/ree5fc719e330f82ae38a2b0050c91f18ed5b878312dc0b9e0b9815be%40%3Cdev.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ree5fc719e330f82ae38a2b0050c91f18ed5b878312dc0b9e0b9815be@%3Cdev.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2019-12419
- https://www.cve.org/CVERecord?id=CVE-2019-12419
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.