Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.
{
"severity": "HIGH",
"github_reviewed_at": "2022-07-01T11:58:52Z",
"cwe_ids": [
"CWE-384"
],
"nvd_published_at": "2017-04-18T16:59:00Z",
"github_reviewed": true
}