CSRF Vulnerability in Apache CXF Fediz Plugin for Spring Framework
CVE-2017-12631
What is CVE-2017-12631?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Apache CXF Fediz plugin for the Spring Framework, specifically impacting versions prior to 1.4.3 for Spring 2.x, 3.x, and 4.x. This vulnerability could allow a malicious actor to manipulate the security context of an application by injecting roles into the end user's session. As a consequence, unauthorized actions may be permitted under the impersonated user's privileges, posing significant security risks for applications utilizing these frameworks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache CXF Fediz 1.4.x prior to 1.4.3
Apache CXF Fediz prior to 1.3.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved