MEDIUM 6.5
GHSA-542g-m3fx-q86f
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService
빠른 조치
GHSA-542g-m3fx-q86f — org.apache.cxf:cxf-rt-rs-security-oauth2: 아래 명령으로 수정 버전으로 올리세요.
# pom.xml: bump <version>4.2.2</version> for org.apache.cxf:cxf-rt-rs-security-oauth2 상세
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard only in the case that someone forgot to enable authentication on the service. Users are recommended to upgrade to version 4.2.2 or 4.1.7, which fixes this issue.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
Maven / org.apache.cxf:cxf-rt-rs-security-oauth2
최초 영향 버전:
4.2.0 수정 버전: 4.2.2 수정
# pom.xml: bump <version>4.2.2</version> for org.apache.cxf:cxf-rt-rs-security-oauth2 Maven / org.apache.cxf:cxf-rt-rs-security-oauth2
최초 영향 버전:
0 수정 버전: 4.1.7 수정
# pom.xml: bump <version>4.1.7</version> for org.apache.cxf:cxf-rt-rs-security-oauth2