CVE-2019-12419
published 2019-11-06CVE-2019-12419: Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability…
PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
13.84%
96.1th percentile
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_cxf | — | — |
| apache | cxf | >= 3.2.0 < 3.2.11 | 3.2.11 |
| apache | cxf | >= 3.3.0 < 3.3.4 | 3.3.4 |
| oracle | commerce_guided_search | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | flexcube_private_banking | — | — |
| oracle | flexcube_private_banking | — | — |
| oracle | retail_order_broker | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability exists in Apache CXF access token services (OpenID Connect) where the authenticated principal is not validated against the supplied clientId parameter — monitor for token requests where the clientId does not match the authenticated principal ↗
- →Attack vector is HTTP and remotely exploitable — inspect HTTP requests to OpenID Connect access token endpoints for mismatched clientId values relative to the authenticated session ↗
- →The exploit requires a stolen authorization code issued to a different client — correlate authorization code issuance and redemption events across different clientId values to detect code theft and cross-client reuse ↗
- →Reference the upstream security advisory for additional technical detail on the vulnerability ↗
- ·Only Apache CXF versions prior to 3.3.4 and 3.2.11 are affected; deployments on patched versions are not vulnerable ↗
- ·The openshift-logging/elasticsearch6-rhel8 container bundles a vulnerable version of apache-cxf but the vulnerable class is not shipped — this component is NOT affected ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Core (Apache CXF) — CVE-2019-12419
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2019-12419 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Core (Apache CXF) — CVE-2019-12419
Oracle Oracle Financial Services Applications Risk Matrix: Core (Apache CXF) vulnerability
CVE: CVE-2019-12419
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Retail Applications Risk Matrix: Order Broker Foundation (CXF) — CVE-2019-12419
vendor_oracle·2020-01-15·CVSS 9.8
CVE-2019-12419 [CRITICAL] Oracle Oracle Retail Applications Risk Matrix: Order Broker Foundation (CXF) — CVE-2019-12419
Oracle Oracle Retail Applications Risk Matrix: Order Broker Foundation (CXF) vulnerability
CVE: CVE-2019-12419
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Red Hat
cxf: OpenId Connect token service does not properly validate the clientId
vendor_redhat·2019-11-06·CVSS 9.8
CVE-2019-12419 [CRITICAL] CWE-287 cxf: OpenId Connect token service does not properly validate the clientId
cxf: OpenId Connect token service does not properly validate the clientId
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.
A flaw was found in cxf in versions prior to 3.2.11 and 3.3.4. The access token services do not properly validate that an authenticated principal is equal to that of the supplied clientId parameter allowing a malicious cl
OSV
Potential session hijack in Apache CXF
osv·2019-11-08
CVE-2019-12419 [CRITICAL] Potential session hijack in Apache CXF
Potential session hijack in Apache CXF
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.
GHSA
Potential session hijack in Apache CXF
ghsa·2019-11-08
CVE-2019-12419 [CRITICAL] CWE-863 Potential session hijack in Apache CXF
Potential session hijack in Apache CXF
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-12419 cxf: OpenId Connect token service does not properly validate the clientId
bugzilla·2020-03-23·CVSS 9.8
CVE-2019-12419 [CRITICAL] CVE-2019-12419 cxf: OpenId Connect token service does not properly validate the clientId
CVE-2019-12419 cxf: OpenId Connect token service does not properly validate the clientId
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.
Reference:
http://cxf.apache.org/security-advisories.data/CVE-2019-12419.txt.asc
Discussion:
Created cxf tracking bugs for this issue:
Affects: fedora-all [bug 1816176]
---
This vulnerability is out of
Bugzilla
CVE-2019-12419 cxf: OpenId Connect token service does not properly validate the clientId [fedora-all]
bugzilla·2020-03-23·CVSS 9.8
CVE-2019-12419 [CRITICAL] CVE-2019-12419 cxf: OpenId Connect token service does not properly validate the clientId [fedora-all]
CVE-2019-12419 cxf: OpenId Connect token service does not properly validate the clientId [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Tenable
Oracle January 2020 Critical Patch Update Contains 255 CVEs
blogs_tenable·2020-01-15
Oracle January 2020 Critical Patch Update Contains 255 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://cxf.apache.org/security-advisories.data/CVE-2019-12419.txt.aschttps://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/r861eb1a9e0250e9150215b17f0263edf62becd5e20fc96251cff59f6%40%3Cdev.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/re7593a274ee0a85d304d5d42c66fc0081c94d7f22bc96a1084d43b80%40%3Cdev.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/ree5fc719e330f82ae38a2b0050c91f18ed5b878312dc0b9e0b9815be%40%3Cdev.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://cxf.apache.org/security-advisories.data/CVE-2019-12419.txt.aschttps://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/r861eb1a9e0250e9150215b17f0263edf62becd5e20fc96251cff59f6%40%3Cdev.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/re7593a274ee0a85d304d5d42c66fc0081c94d7f22bc96a1084d43b80%40%3Cdev.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/ree5fc719e330f82ae38a2b0050c91f18ed5b878312dc0b9e0b9815be%40%3Cdev.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2019-11-06
Published