CyberRota Analysis
AI-GeneratedApache CXF is vulnerable due to a flaw in the DefaultEncryptingCodeDataProvider, allowing a captured authorization code to be reused indefinitely, which violates RFC standards. This critical vulnerability poses a significant risk of unauthorized access, potentially compromising sensitive data and user accounts. Organizations using affected versions should prioritize upgrading to versions 4.2.3, 4.1.8, or 3.6.12 to mitigate this risk.
Original NVD Description
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)