The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cxf | Apache | * | 3.0.12 (including) |
Cxf | Apache | 3.1.0 (including) | 3.1.0 (including) |
Cxf | Apache | 3.1.1 (including) | 3.1.1 (including) |
Cxf | Apache | 3.1.2 (including) | 3.1.2 (including) |
Cxf | Apache | 3.1.3 (including) | 3.1.3 (including) |
Cxf | Apache | 3.1.4 (including) | 3.1.4 (including) |
Cxf | Apache | 3.1.5 (including) | 3.1.5 (including) |
Cxf | Apache | 3.1.6 (including) | 3.1.6 (including) |
Cxf | Apache | 3.1.7 (including) | 3.1.7 (including) |
Cxf | Apache | 3.1.8 (including) | 3.1.8 (including) |
Cxf | Apache | 3.1.9 (including) | 3.1.9 (including) |
Red Hat JBoss A-MQ 6.3 | RedHat | cxf | * |
Red Hat JBoss Fuse 6.3 | RedHat | cxf | * |