CVE-2017-3156

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
apachecxf
𝑥
≤ 3.0.12
apachecxf
3.1.0
apachecxf
3.1.1
apachecxf
3.1.2
apachecxf
3.1.3
apachecxf
3.1.4
apachecxf
3.1.5
apachecxf
3.1.6
apachecxf
3.1.7
apachecxf
3.1.8
apachecxf
3.1.9
𝑥
= Vulnerable software versions
References