Cross-Site Request Forgery Vulnerability in Apache CXF Fediz Plugins
CVE-2017-7661
8.8HIGH
Summary
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Apache CXF Fediz, specifically within certain container-specific plugins that enable WS-Federation for applications. This affects multiple versions including those in the Spring and Jetty plugin frameworks, allowing potential malicious requests to be executed without user consent, thus compromising application integrity. Users are encouraged to upgrade to the latest versions to mitigate any risks associated with this vulnerability.
Affected Version(s)
Apache CXF Fediz prior to 1.4.0, 1.3.2 and 1.2.4.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved