Apache CXF OpenId Connect JWK Service Vulnerability to Key Exfiltration
CVE-2019-12423
7.5HIGH
Summary
Apache CXF includes a service for OpenId Connect JWK keys that can inadvertently expose sensitive private and secret key credentials if a JWK keystore file is misconfigured. If the parameter 'rs.security.keystore.type' is set to 'jwk', all keys from the specified keystore, including confidential information, are returned in an unsecured manner. This vulnerability can lead to unauthorized access and manipulation of secure tokens, jeopardizing the integrity of the authentication process unless properly configured with aliases for keys.
Affected Version(s)
CXF All versions of Apache CXF prior to 3.3.5 and 3.2.12.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved