GHSA-542g-m3fx-q86fMediumCVSS 6.5
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService
🔗 CVE IDs covered (1)
📋 Description
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard only in the case that someone forgot to enable authentication on the service. Users are recommended to upgrade to version 4.2.2 or 4.1.7, which fixes this issue.
🎯 Affected products2
- maven/org.apache.cxf:cxf-rt-rs-security-oauth2:>= 4.2.0, < 4.2.2
- maven/org.apache.cxf:cxf-rt-rs-security-oauth2:< 4.1.7