CyberRota Analysis
AI-GeneratedApache CXF's DefaultEncryptingOAuthDataProvider is vulnerable as it allows revoked access and refresh tokens to still decrypt successfully, falsely reporting them as active. This non-compliance with RFC standards poses a significant security risk, as it undermines token invalidation processes. Organizations using affected versions should prioritize upgrading to 4.2.3, 4.1.8, or 3.6.12 to mitigate potential unauthorized access.
Original NVD Description
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)