CVE Vulnerabilities

CVE-2017-3156

Published: Aug 10, 2017 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

Affected Software

Name Vendor Start Version End Version
Cxf Apache * 3.0.12 (including)
Cxf Apache 3.1.0 (including) 3.1.0 (including)
Cxf Apache 3.1.1 (including) 3.1.1 (including)
Cxf Apache 3.1.2 (including) 3.1.2 (including)
Cxf Apache 3.1.3 (including) 3.1.3 (including)
Cxf Apache 3.1.4 (including) 3.1.4 (including)
Cxf Apache 3.1.5 (including) 3.1.5 (including)
Cxf Apache 3.1.6 (including) 3.1.6 (including)
Cxf Apache 3.1.7 (including) 3.1.7 (including)
Cxf Apache 3.1.8 (including) 3.1.8 (including)
Cxf Apache 3.1.9 (including) 3.1.9 (including)
Red Hat JBoss A-MQ 6.3 RedHat cxf *
Red Hat JBoss Fuse 6.3 RedHat cxf *

References