PT-2026-80274 · Maven · Org.Apache.Cxf:Cxf-Rt-Rs-Security-Oauth2

Publicado

2026-06-12

·

Atualizado

2026-06-12

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this
security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Correção

Improperly Implemented Security Check for Standard

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-G5V7-JCHF-7JRR

Produtos afetados

Org.Apache.Cxf:Cxf-Rt-Rs-Security-Oauth2