CVE Database
/

CVE-2019-12419

Back to search

CVE-2019-12419

Published: Nov 6, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

VendorProductVersions

Apache

Apache CXF

affected
versions before 3.3.4 and 3.2.11

References

[cxf-dev] 20201030 CVE-2019-12419
mailing-list
x_refsource_MLIST
[cxf-dev] 20201102 Re: CVE-2019-12419
mailing-list
x_refsource_MLIST
[cxf-dev] 20201103 Re: CVE-2019-12419
mailing-list
x_refsource_MLIST

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now