CSRF Vulnerability in Apache CXF Fediz Plugin for Spring Framework
CVE-2017-12631
8.8HIGH
What is CVE-2017-12631?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Apache CXF Fediz plugin for the Spring Framework, specifically impacting versions prior to 1.4.3 for Spring 2.x, 3.x, and 4.x. This vulnerability could allow a malicious actor to manipulate the security context of an application by injecting roles into the end user's session. As a consequence, unauthorized actions may be permitted under the impersonated user's privileges, posing significant security risks for applications utilizing these frameworks.
Affected Version(s)
Apache CXF Fediz 1.4.x prior to 1.4.3
Apache CXF Fediz prior to 1.3.3