CyberRota Analysis
AI-GeneratedApache CXF implementations that utilize the Hybrid Flow of the OpenID Connect Core 1.0 specification are vulnerable if integrated with non-compliant or misconfigured Identity Providers that do not validate the `c_hash` parameter. This vulnerability can lead to Authorization Code Substitution/Injection attacks, potentially compromising user authentication and authorization processes. Organizations using affected versions should prioritize upgrading to at least versions 4.2.3, 4.1.8, or 3.6.12 to mitigate this risk.
Original NVD Description
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)