CVE Vulnerabilities

CVE-2017-3156

Published: Aug 10, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

Affected Software

NameVendorStart VersionEnd Version
CxfApache*3.0.12 (including)
CxfApache3.1.0 (including)3.1.0 (including)
CxfApache3.1.1 (including)3.1.1 (including)
CxfApache3.1.2 (including)3.1.2 (including)
CxfApache3.1.3 (including)3.1.3 (including)
CxfApache3.1.4 (including)3.1.4 (including)
CxfApache3.1.5 (including)3.1.5 (including)
CxfApache3.1.6 (including)3.1.6 (including)
CxfApache3.1.7 (including)3.1.7 (including)
CxfApache3.1.8 (including)3.1.8 (including)
CxfApache3.1.9 (including)3.1.9 (including)
Red Hat JBoss A-MQ 6.3RedHatcxf*
Red Hat JBoss Fuse 6.3RedHatcxf*

References