CyberRota Analysis
AI-GeneratedA race condition in JCacheCodeDataProvider enables attackers to exploit concurrent requests to redeem a single authorization code multiple times, leading to the issuance of multiple valid access tokens. This vulnerability poses a significant risk to systems relying on authorization code flows, potentially allowing unauthorized access to sensitive resources. Organizations using affected versions should prioritize upgrading to versions 4.2.3, 4.1.8, or 3.6.12 to mitigate this high-severity issue.
Original NVD Description
A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)