The vendor explicitly identifies these products as affected by this CVE.
- cxf-rt-rs-security-oauth2 as a component of Red Hat build of Apache Camel for Spring Boot 4
- cxf-rt-rs-security-oauth2 as a component of Red Hat JBoss Web Server 5
- Summary
- A flaw was found in Apache CXF's DefaultEncryptingCodeDataProvider. This vulnerability allows a remote attacker to redeem a captured authorization code an unlimited number of times. The flaw exists due to an issue in the `removeCodeGrant` functionality, which fails to properly invalidate used authorization codes. This can lead to unauthorized access or session hijacking, violating the security principle that authorization codes should only be used once.
- Remediation
- Affected
