CVE-2017-5656
published 2017-04-18CVE-2017-5656: Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker…
PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
6.83%
93.3th percentile
Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | >= 3.0.0 < 3.0.13 | 3.0.13 |
| apache | cxf | >= 3.1.0 < 3.1.11 | 3.1.11 |
| apache_software_foundation | apache_cxf | — | — |
| apache_software_foundation | apache_cxf | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Session Fixation in Apache CXF
osv·2022-05-13
CVE-2017-5656 [HIGH] Session Fixation in Apache CXF
Session Fixation in Apache CXF
Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.
GHSA
Session Fixation in Apache CXF
ghsa·2022-05-13
CVE-2017-5656 [HIGH] CWE-384 Session Fixation in Apache CXF
Session Fixation in Apache CXF
Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.
Red Hat
cxf: CXF's STSClient uses a flawed way of caching tokens that are associated with delegation tokens
vendor_redhat·2017-04-05·CVSS 7.5
CVE-2017-5656 [HIGH] cxf: CXF's STSClient uses a flawed way of caching tokens that are associated with delegation tokens
cxf: CXF's STSClient uses a flawed way of caching tokens that are associated with delegation tokens
Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.
It was found that the token cacher in Apache cxf uses a flawed way of caching tokens that are associated with the delegation token received from Security Token Service (STS). This vulnerability could allow an attacker to craft a token which could return an identifier corresponding to a cached token for another user.
Package: cxf (Red Hat BPM Suite 6) - Not affected
Package: cxf (Red Hat JBoss BRMS 5) - Not affected
Package: cxf (Red
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5653 CVE-2017-5656 cxf: various flaws [fedora-all]
bugzilla·2017-04-25·CVSS 5.3
CVE-2017-5653 [MEDIUM] CVE-2017-5653 CVE-2017-5656 cxf: various flaws [fedora-all]
CVE-2017-5653 CVE-2017-5656 cxf: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
Bugzilla
CVE-2017-5656 cxf: CXF's STSClient uses a flawed way of caching tokens that are associated with delegation tokens
bugzilla·2017-04-25·CVSS 7.5
CVE-2017-5656 [HIGH] CVE-2017-5656 cxf: CXF's STSClient uses a flawed way of caching tokens that are associated with delegation tokens
CVE-2017-5656 cxf: CXF's STSClient uses a flawed way of caching tokens that are associated with delegation tokens
An Apache CXF endpoint can be used as an intermediary, where a token credential
from the received message is used as a delegation token to obtain a new token
from a Security Token Service (STS) for the outbound request.
By default, the token retrieved from the STS is cached and associated with the
delegation token via an identifier extracted from the delegation token.
However, there is a weakness in how the identifier is extracted from the
delegation token, which means that an attacker could craft a token which
would return an identifer corresponding to a cached token for another user.
External References:
http://cxf.apache.org/security-advisories.data/CVE-2017-5656.txt.as
http://cxf.apache.org/security-advisories.data/CVE-2017-5656.txt.asc?version=1&modificationDate=1492515113282&api=v2http://www.securityfocus.com/bid/97971http://www.securitytracker.com/id/1038282https://access.redhat.com/errata/RHSA-2017:1832https://access.redhat.com/errata/RHSA-2018:1694https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttp://cxf.apache.org/security-advisories.data/CVE-2017-5656.txt.asc?version=1&modificationDate=1492515113282&api=v2http://www.securityfocus.com/bid/97971http://www.securitytracker.com/id/1038282https://access.redhat.com/errata/RHSA-2017:1832https://access.redhat.com/errata/RHSA-2018:1694https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E
2017-04-18
Published