CVE Published: 18/04/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache CXF Status : PUBLISHED
CVE-2017-5656 Description
Apache CXF\'s STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.
CWE-ID: CWE Name: Apache CXF
s STSClient uses a flawed way of caching tokens that are associated with delegation tokens. Source: Apache Software Foundation
Common Attack Pattern Enumeration and Classification (CAPEC)