Cross-Site Request Forgery Vulnerability in Apache CXF Fediz Plugins
CVE-2017-7661
8.8HIGH
What is CVE-2017-7661?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Apache CXF Fediz, specifically within certain container-specific plugins that enable WS-Federation for applications. This affects multiple versions including those in the Spring and Jetty plugin frameworks, allowing potential malicious requests to be executed without user consent, thus compromising application integrity. Users are encouraged to upgrade to the latest versions to mitigate any risks associated with this vulnerability.
Affected Version(s)
Apache CXF Fediz prior to 1.4.0, 1.3.2 and 1.2.4.