Back

CRITICAL

cxf: OpenId Connect token service does not properly validate the clientId

Published Nov 6, 2019

Description

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

Affected products

Remediation

Red Hat statement

In OpenShift Logging the openshift-logging/elasticsearch6-rhel8 container bundles the vulnerable version of apache-cxf, but the vulnerable class is not shipped, hence this component is not affected by this vulnerability.

References (29)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Nov 6, 2019
Updated Aug 4, 2024
Reserved May 28, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 6, 2019
ENISA EUVD
Assigner apache
Published Nov 6, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-0745 GHSA-CW6W-Q88J-6MQF