GHSA-j473-c3rr-rx9p

Suggest an improvement
Source
https://github.com/advisories/GHSA-j473-c3rr-rx9p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j473-c3rr-rx9p/GHSA-j473-c3rr-rx9p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j473-c3rr-rx9p
Aliases
Published
2022-05-17T05:15:11Z
Modified
2025-04-12T03:12:08.999772Z
Summary
OpenID4Java does not verify that Attribute Exchange (AX) information is signed
Details

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

Database specific
{
    "nvd_published_at": "2012-01-27T15:55:00Z",
    "severity": "MODERATE",
    "github_reviewed_at": "2025-04-12T02:28:13Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-20",
        "CWE-345"
    ]
}
References

Affected packages

Maven / org.openid4java:openid4java

Package

Name
org.openid4java:openid4java
View open source insights on deps.dev
Purl
pkg:maven/org.openid4java/openid4java

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.6

Affected versions

0.*

0.9.2
0.9.3
0.9.4.339
0.9.5