CVE-2016-4464 (cxf_fediz)

CVE-2016-4464 (cxf_fediz)

The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers to have bypass intended restrictions and have unspecified other impact via a crafted SAML token with a trusted signature.

Source: CVE-2016-4464 (cxf_fediz)

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다