VDB
EN
MEDIUM 6.5

GHSA-542g-m3fx-q86f

Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService

빠른 조치

GHSA-542g-m3fx-q86f — org.apache.cxf:cxf-rt-rs-security-oauth2: 아래 명령으로 수정 버전으로 올리세요.

# pom.xml: bump <version>4.2.2</version> for org.apache.cxf:cxf-rt-rs-security-oauth2

상세

An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard only in the case that someone forgot to enable authentication on the service. Users are recommended to upgrade to version 4.2.2 or 4.1.7, which fixes this issue.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Maven / org.apache.cxf:cxf-rt-rs-security-oauth2
최초 영향 버전: 4.2.0 수정 버전: 4.2.2
수정 # pom.xml: bump <version>4.2.2</version> for org.apache.cxf:cxf-rt-rs-security-oauth2
Maven / org.apache.cxf:cxf-rt-rs-security-oauth2
최초 영향 버전: 0 수정 버전: 4.1.7
수정 # pom.xml: bump <version>4.1.7</version> for org.apache.cxf:cxf-rt-rs-security-oauth2

참고