Security Advisory

CVE-2017-3156

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-08-10 18:00:00
Last updated 2024-09-16 23:16:01
Assigner apache
CVSS score not scored
State PUBLISHED

Description

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.