CyberRota Analysis
AI-GeneratedApache CXF's JwtRequestCodeFilter is vulnerable as it improperly handles claims from signed JWTs, allowing attackers with access to a valid client_secret to manipulate critical parameters like code_challenge and nonce. This flaw compromises the integrity of the PKCE mechanism and exposes systems to potential replay attacks in OpenID Connect implementations. Organizations using affected versions of Apache CXF should prioritize upgrading to versions 4.2.3, 4.1.8, or 3.6.12 to mitigate this critical risk.
Original NVD Description
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)