Apache CXF OpenId Connect JWK Service Vulnerability to Key Exfiltration
CVE-2019-12423
What is CVE-2019-12423?
Apache CXF includes a service for OpenId Connect JWK keys that can inadvertently expose sensitive private and secret key credentials if a JWK keystore file is misconfigured. If the parameter 'rs.security.keystore.type' is set to 'jwk', all keys from the specified keystore, including confidential information, are returned in an unsecured manner. This vulnerability can lead to unauthorized access and manipulation of secure tokens, jeopardizing the integrity of the authentication process unless properly configured with aliases for keys.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CXF All versions of Apache CXF prior to 3.3.5 and 3.2.12.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved