Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFwd2otbXZ2Ny12M205

High severity vulnerability that affects org.apache.cxf.fediz:fediz-spring and org.apache.cxf.fediz:fediz-spring2

The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers to have bypass intended restrictions and have unspecified other impact via a crafted SAML token with a trusted signature.

Permalink: https://github.com/advisories/GHSA-qpwj-mvv7-v3m9
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFwd2otbXZ2Ny12M205
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 5 years ago
Updated: about 1 year ago


Identifiers: GHSA-qpwj-mvv7-v3m9, CVE-2016-4464
References: Repository: https://git-wip-us.apache.org/repos/asf/cxf-fediz
Blast Radius: 0.0

Affected Packages

maven:org.apache.cxf.fediz:fediz-spring2
Dependent packages: 4
Dependent repositories: 2
Downloads:
Affected Version Ranges: = 1.3.0, >= 1.2.0, < 1.2.3
Fixed in: 1.3.1, 1.2.3
All affected versions: 1.2.0, 1.2.1, 1.2.2, 1.3.0
All unaffected versions: 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.2.3, 1.2.4, 1.3.1, 1.3.2, 1.3.3, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6
maven:org.apache.cxf.fediz:fediz-spring
Dependent packages: 9
Dependent repositories: 8
Downloads:
Affected Version Ranges: = 1.3.0, >= 1.2.0, < 1.2.3
Fixed in: 1.3.1, 1.2.3
All affected versions: 1.2.0, 1.2.1, 1.2.2, 1.3.0
All unaffected versions: 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.2.3, 1.2.4, 1.3.1, 1.3.2, 1.3.3, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.5.0, 1.5.1, 1.6.0, 1.6.1, 1.6.2