Apache CXF OpenId Connect JWK Service Vulnerability to Key Exfiltration
CVE-2019-12423

7.5HIGH

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
16 January 2020

Summary

Apache CXF includes a service for OpenId Connect JWK keys that can inadvertently expose sensitive private and secret key credentials if a JWK keystore file is misconfigured. If the parameter 'rs.security.keystore.type' is set to 'jwk', all keys from the specified keystore, including confidential information, are returned in an unsecured manner. This vulnerability can lead to unauthorized access and manipulation of secure tokens, jeopardizing the integrity of the authentication process unless properly configured with aliases for keys.

Affected Version(s)

CXF All versions of Apache CXF prior to 3.3.5 and 3.2.12.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.