Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFwd2otbXZ2Ny12M205
High severity vulnerability that affects org.apache.cxf.fediz:fediz-spring and org.apache.cxf.fediz:fediz-spring2
The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers to have bypass intended restrictions and have unspecified other impact via a crafted SAML token with a trusted signature.
Permalink: https://github.com/advisories/GHSA-qpwj-mvv7-v3m9JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFwd2otbXZ2Ny12M205
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 6 years ago
Updated: almost 2 years ago
Identifiers: GHSA-qpwj-mvv7-v3m9, CVE-2016-4464
References:
- https://nvd.nist.gov/vuln/detail/CVE-2016-4464
- https://git-wip-us.apache.org/repos/asf?p=cxf-fediz.git;a=commit;h=0006581e9cacbeef46381a223e5671e524d416b6
- https://github.com/advisories/GHSA-qpwj-mvv7-v3m9
- https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e@%3Ccommits.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E
- http://cxf.apache.org/security-advisories.data/CVE-2016-4464.txt.asc
- http://www.openwall.com/lists/oss-security/2016/09/08/20
- http://www.securityfocus.com/bid/92905
- http://www.securitytracker.com/id/1036869
Blast Radius: 0.0
Affected Packages
maven:org.apache.cxf.fediz:fediz-spring2
Dependent packages: 4Dependent repositories: 2
Downloads:
Affected Version Ranges: = 1.3.0, >= 1.2.0, < 1.2.3
Fixed in: 1.3.1, 1.2.3
All affected versions: 1.2.0, 1.2.1, 1.2.2, 1.3.0
All unaffected versions: 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.2.3, 1.2.4, 1.3.1, 1.3.2, 1.3.3, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6
maven:org.apache.cxf.fediz:fediz-spring
Dependent packages: 9Dependent repositories: 8
Downloads:
Affected Version Ranges: = 1.3.0, >= 1.2.0, < 1.2.3
Fixed in: 1.3.1, 1.2.3
All affected versions: 1.2.0, 1.2.1, 1.2.2, 1.3.0
All unaffected versions: 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.2.3, 1.2.4, 1.3.1, 1.3.2, 1.3.3, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.5.0, 1.5.1, 1.6.0, 1.6.1, 1.6.2, 1.7.0