Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache CXF 输入验证错误漏洞
Vulnerability Description
Apache CXF是美国阿帕奇(Apache)基金会的一个开源的Web服务框架。该框架支持多种Web服务标准、多种前端编程API等。 Apache CXF 2.6.11及之前的版本和2.7.9之前的2.7.x版本中的SecurityTokenService(STS)存在输入验证错误漏洞,该漏洞源于程序没有正确验证SAML令牌。远程攻击者可借助无效的SAML令牌利用该漏洞获取访问权限。
CVSS Information
N/A
Vulnerability Type
N/A