CVE-2014-0034
published 2014-07-07CVE-2014-0034: The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows…
PriorityP335medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
7.41%
93.7th percentile
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | <= 2.6.11 | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Input Validation in Apache CXF
ghsa·2022-05-13
CVE-2014-0034 [MEDIUM] CWE-20 Improper Input Validation in Apache CXF
Improper Input Validation in Apache CXF
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.
OSV
Improper Input Validation in Apache CXF
osv·2022-05-13
CVE-2014-0034 [MEDIUM] Improper Input Validation in Apache CXF
Improper Input Validation in Apache CXF
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.
Red Hat
CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid
vendor_redhat·2014-05-01·CVSS 4.3
CVE-2014-0034 [MEDIUM] CWE-345 CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid
CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.
It was found that the SecurityTokenService (STS), provided as a part of Apache CXF, could under certain circumstances accept invalid SAML tokens as valid. A remote attacker could use a specially crafted SAML token to gain access to an application that uses STS for validation of SAML tokens.
Package: cxf (OpenShift Enterprise 1) - Will not fix
Package: cxf (Red Hat BPM Suite 6) - Affected
Package: cxf (Red Hat JBoss BRMS 5) - Will not fix
Package: cxf (Red Hat JBoss BRMS 6) - Affected
Package: cx
No detection rules found.
Bugzilla
CVE-2014-0034 Apache CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid [fedora-all]
bugzilla·2014-05-07·CVSS 4.3
CVE-2014-0034 [MEDIUM] CVE-2014-0034 Apache CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid [fedora-all]
CVE-2014-0034 Apache CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availabl
Bugzilla
CVE-2014-0034 Apache CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid
bugzilla·2014-05-02·CVSS 4.3
CVE-2014-0034 [MEDIUM] CVE-2014-0034 Apache CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid
CVE-2014-0034 Apache CXF: The SecurityTokenService accepts certain invalid SAML Tokens as valid
The SecurityTokenService (STS) provided as part of Apache CXF has bindings to
issue, validate, renew and cancel tokens. The main use-case is to issue SAML
tokens. However, a less common use-case is to use the STS to validate SAML
tokens. The vulnerability is that there are certain circumstances in which the
STS will accept an invalid SAML token as valid if caching is enabled.
Affected versions:
Apach CXF 2.6.x < 2.6.12
Apach CXF 2.7.x < 2.7.9
Note from apache advisory:
Although this vulnerability has been fixed in CXF 2.6.12 and 2.7.9, due to
other security advisories it is recommended to upgrade to the following
releases:
CXF 2.6.x users should upgrade to 2.6.14 or later as soon as possible.
Bugzilla
CVE-2014-0171 Odata4j: XML eXternal Entity (XXE) flaw
bugzilla·2014-04-08·CVSS 5.0
CVE-2014-0171 [MEDIUM] CVE-2014-0171 Odata4j: XML eXternal Entity (XXE) flaw
CVE-2014-0171 Odata4j: XML eXternal Entity (XXE) flaw
IssueDescription:
It was found that Odata4j permitted XML eXternal Entity (XXE) attacks. If a REST endpoint was deployed, a remote attacker could submit a request containing an external XML entity that, when resolved, allowed that attacker to read files on the application server in the context of the user running that server.
Discussion:
Acknowledgements:
This issue was discovered by David Jorm of Red Hat Product Security.
---
Fixed in
https://issues.jboss.org/secure/attachment/12381735/org.odata4j.stax2.staximpl.StaxXMLFactoryProvider2.diff
or a later attachment in
https://issues.jboss.org/browse/TEIID-2911
---
This issue has been addressed in the following products:
JBoss Data Virtualization 6.0.0
Via RHSA-2015:0034 http
http://cxf.apache.org/security-advisories.data/CVE-2014-0034.txt.aschttp://rhn.redhat.com/errata/RHSA-2014-0797.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0798.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0799.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1351.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1551228http://www.securityfocus.com/bid/68441https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttp://cxf.apache.org/security-advisories.data/CVE-2014-0034.txt.aschttp://rhn.redhat.com/errata/RHSA-2014-0797.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0798.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0799.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1351.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1551228http://www.securityfocus.com/bid/68441https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E
2014-07-07
Published